INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Ransomware Attacks Target Japanese Companies with AI-Powered Malware
| 2026-10-01 12:56 CRITICAL HIGH AI-ENABLED ATTACK RANSOMWARE & EXTORTION MALWARE & BOTNETS
Executive Summary
AI-generated
Ransomware incidents have been on the rise globally, with Japan experiencing a 4.7% increase in ransomware attacks during the first half of 2026 compared to the same period last year. The Gentlemen was identified as the most active ransomware group in this time frame, potentially involving Russian-speaking individuals. A total of 90 organizations were affected by these attacks, with Taiwan recording the highest number of incidents followed by the United States and Philippines. Meanwhile, a prominent accounting firm, Krycler, Ervin, Taubman & Kaminsky, has been targeted by ransomware operators, resulting in an 88gb data breach. This incident highlights the growing threat of cyber attacks on businesses worldwide.
Technical Mitigations AI-generated
• Implementing robust backups and disaster recovery plans to minimize data loss in the event of a ransomware attack.
• Utilizing endpoint security solutions, such as antivirus software and intrusion detection systems, to detect and prevent ransomware infections on individual devices.
• Conducting regular network segmentation and isolation techniques to limit the spread of ransomware within an organization's network.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
CVE-2025-24799CVE-2025-24799
CVE-2020-1472CVE-2020-1472
CVE-2025-2479CVE-2025-2479
Target & Sectors
TW
JP
RU
manufacturingmanufacturing
financefinance
transportationtransportation
legallegal
retailretail
healthhealth
Incident Timeline
January to 87
The number of victims targeted by Akira increased sharply from 48 in January to 87 in February.
around July 2025
The Gentlemen ransomware group has been active since around July 2025, targeting victims including Krycler, Ervin, Taubman & Kaminsky.
Click on any entity below to view its context and source!
tactic
Ransomware
Overview of The Gentlemen ransomware
The Gentlemen ransomware group has been active since around July 2025.
2025/09/17
Ransomware incidents in Japan increased by approximately 4.7% compared to the same period last year, with a total of around 86 reported incidents from January to July this year.
Click on any entity below to view its context and source!
tactic
Ransomware
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.
Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level.
Looking at the ransomware groups observed this year, very few of the groups that were active during the same period last year have been observed, highlighting the rapid changes in the ransomware threat landscape.
target_region
Japan
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.
general_metric
4.7 %
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.
Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level.
general_metric
86 incidents
Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level.
malware
Qilin
This was followed by Qilin, which caused the highest number of incidents last year, and SafePay, which had relatively few confirmed incidents during the same period last year, with seven incidents each.
organisation
SafePay
This was followed by Qilin, which caused the highest number of incidents last year, and SafePay, which had relatively few confirmed incidents during the same period last year, with seven incidents each.
January to July 2026
Threat actors used ransomware to target Japanese companies, resulting in the publication of a new victim.
Click on any entity below to view its context and source!
tactic
Ransomware
Victimized companies
Figure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026.
target_region
Japan
Victimized companies
Figure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026.
general_metric
1 companies
Victimized companies
Figure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026.
January – July 2026
Threat actors used The Gentlemen leak site to publish a new victim listing for Krycler, Ervin, Taubman & Kaminsky between January and July 2026.
2026/10/01
The threat actor Qilin leveraged AI to improve the efficiency of its operations, using a tool that periodically sent ping requests to a specified IP address and logged whether the host was reachable.
Click on any entity below to view its context and source!
organisation
SSN
lots of employee documents (passports, DLs, SSN, de
ath and birth certs), financials, insurance, credit cards, client information, NDAs and so on.
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
infrastructure
Windows
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
Our investigation found ransomware targeting ESXi and Windows environments linked to The Gentlemen.
The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain.
This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain.
The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec.
This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status.
organisation
/mnt/Backup
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
organisation
VHDX
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
victims
90 organizations
According to Cisco Talos research, 90 organizations in Japan were affected by ransomware during this period.
organisation
NightSpire
Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock.
organisation
LockBit 5.0
Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock.
organisation
AiLock
Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock.
organisation
LLM
We also identified traces of code that appears to have been generated by an LLM in “deploy_locker.py”, a script used to distribute and execute ransomware across multiple endpoints.
organisation
Ervin, Taubman & Kaminsky
Akira has just published a new victim : Krycler, Ervin, Taubman & Kaminsky.
organisation
Krycler
Krycler, Ervin, Taubman & Kaminsky
Description:
Krycler, Ervin, Taubman & Kaminsky is a prominent accounting, litigation support, and consultin
g firm based in Sherman Oaks, California.
data_breach
88 gb
We will upload 88gb of corporate data soon.
organisation
GPO
The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain.
organisation
Active Directory Group Policy
This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain.
organisation
Windows/Active Directory
This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status.
organisation
NetExec
The actor then repeatedly installs and configures reconnaissance tools such as nmap and masscan, along with BloodHound, NetExec, Responder, and Impacket for targeting AD environments, all within the same command history.
organisation
Proofs
Following target selection, during Phase 3, we observed the actor downloading and executing Proofs of concept, reconnaissance scripts, and attack tools associated with known vulnerabilities against publicly exposed web services and administrative interfaces.
organisation
RustHound
They may also have used RustHound/BloodHound-related tools to collect domain users, groups, computers, administrative privileges, and trust relationships, with the aim of identifying paths that could be used for lateral movement and privilege escalation.
organisation
BloodHound
We also identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
SQL
We also identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
Responder
We also identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
NTLM
We also identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
AnyDesk
We also identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
Rclone
We also identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
RDP
They then used NetExec and Impacket to attempt authentication to services such as SMB, LDAP, RDP, and WinRM, seeking access to multiple hosts and attempting lateral movement.
organisation
CVE-2025-24799
Specifically, the actor attempted to exploit CVE-2025-24799, an unauthenticated SQL injection vulnerability in GLPI, using both a PoC and sqlmap to retrieve user information from the database.
organisation
PoC
Specifically, the actor attempted to exploit CVE-2025-24799, an unauthenticated SQL injection vulnerability in GLPI, using both a PoC and sqlmap to retrieve user information from the database.
organisation
SAM
The command history records the installation of libguestfs-tools, qemu-utils, and nbd-client, the creation of directories such as /mnt/vhdx, and the copying of ntds.dit, SAM, and SYSTEM.
organisation
Chisel
In Phase 1, the actor uses VPN software and tools such as Chisel and Ligolo to establish network routes and turn its server into an attack platform.
organisation
Nmap
They appear to have used Masscan and Nmap to assess publicly exposed hosts, VPN-related ports, web services, SMB, and other active services in order to understand the external and internal network structure.
organisation
SMB
They appear to have used Masscan and Nmap to assess publicly exposed hosts, VPN-related ports, web services, SMB, and other active services in order to understand the external and internal network structure.
organisation
Active Directory
Upon gaining access to the internal network, they used NetExec to enumerate SMB shares, host information, LDAP, and computer information in Active Directory.
organisation
cPanel/WHM
The actor also used a scanner targeting cPanel/WHM and downloaded and executed a PoC to test for authentication bypass vulnerabilities.
organisation
SSH
The actor used VPN, Chisel, Ligolo-ng, SSH, and Proxychains to establish communication paths from the attacker-controlled server into the target organization’s internal network.
organisation
HTTP/S
In addition, it supports multiple communication protocols, including HTTP/S, DNS/DoH, and SMB, making it adaptable to various network environments.
organisation
DNS/DoH
In addition, it supports multiple communication protocols, including HTTP/S, DNS/DoH, and SMB, making it adaptable to various network environments.
organisation
IP
The tool itself is relatively simple, periodically sending ping requests to a specified IP address and logging whether the host is reachable.
organisation
the .bash_history File
Contents of the .bash_history File (excerpt).
organisation
MFA
To prevent the abuse of credentials, organizations should implement multi-factor authentication (MFA) for VPNs, cloud services, remote desktop services, and administrative accounts.
organisation
EDR
To limit the spread of an attack, it is also effective to use EDR and other security tools to monitor activities such as suspicious remote access, the acquisition of administrative privileges, the disabling of backup functions, and large-scale file modifications.
organisation
SNORT®
Coverage
The following SNORT® rules (SIDs) detect and block this threat:
data_breach
100 number
In June, however, the number exceeded 100 for the first time, reaching 108, and remained high at 105 in July.
data_breach
16 files
The VHDX file was split into 256MiB chunks, with up to 16 files uploaded concurrently to reduce the overall upload time.
the first half of 2026
The Gentlemen ransomware group was the most frequently observed in Japan during the first half of 2026, resulting in 14 incidents.
Click on any entity below to view its context and source!
organisation
Ransomware
Ransomware incidents in Japan in the first half of 2026:
In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.
Ransomware incidents in Japan during the first half of 2026 (January through July).
Most frequently observed ransomware types in Japan
In Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents.
target_region
Japan
Ransomware incidents in Japan in the first half of 2026:
In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.
Ransomware incidents in Japan during the first half of 2026 (January through July).
Most frequently observed ransomware types in Japan
In Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents.
general_metric
14 incidents
Most frequently observed ransomware types in Japan
In Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents.
Tactical Metrics
Metrics
data_breach
88
Gb
Click for context!
We will upload 88gb of corporate data soon.
Metrics
victims
90
Organizations
According to Cisco Talos research, 90 organizations in Japan were affected by ransomware during this period.
Metrics
infrastructure
Windows
Affected Product
Our investigation found ransomware targeting ESXi and Windows environments linked to The Gentlemen.
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain.
This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain.
The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec.
This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status.
Metrics
data_breach
100
Number
In June, however, the number exceeded 100 for the first time, reaching 108, and remained high at 105 in July.
Metrics
data_breach
16
Files
The VHDX file was split into 256MiB chunks, with up to 16 files uploaded concurrently to reduce the overall upload time.
Intelligence Sources
Talos Intelligence
2026-09-17
Ransomware Live
2026-10-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T15:29
Comprehensive Tactical Telemetry
Highly Correlated Entities
41x
organisation
Identified Entity
SSN
entity
15x
general metric
%
5
%
12x
timeline
Temporal Reference
the first half of 2026
date
8x
tactic
Cyber Operation Type
Exfiltration
tactic
6x
industry
Targeted Sector
Legal
sector
3x
target region
Target Country
Japan
country
3x
source region
Origin Country
United States
country
3x
general metric
Incidents
14
incidents
3x
vulnerability
Exploited CVE
CVE-2025-2479
cve
3x
general metric
Listings
70
listings
2x
general metric
Phase
2
phase
2x
general metric
Jpy
1,000,000,000
jpy
Contextual Telemetry
Context Block
11 METRICS
data breach
Gb
88
gb
victims
Organizations
90
organizations
general metric
Companies
1
companies
infrastructure
Affected Product
Windows
software
malware
Offensive Tool
Bloodhound
tool
malware
Malware Payload
Qilin
tool
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
general metric
- Fold Increase
2
- fold increase
data breach
Number
100
number
general metric
Time
108
time
data breach
Files
16
files
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.