Japan Ransomware: The Gentlemen and Qilin AI Use | #ransomware | #cybercrime



Summary

Ransomware activity in Japan increased slightly during the first half of 2026, with The Gentlemen and Qilin emerging as two notable groups. The Gentlemen operated through a Ransomware-as-a-Service model and relied on double-extortion tactics, while Qilin showed signs of using generative AI to create deployment scripts. Small- and medium-sized enterprises across multiple industries were the primary targets.

Investigation

The investigation examined The Gentlemen’s open-directory infrastructure and command history, revealing a multi-stage attack lifecycle spanning network tunneling, lateral movement, and data exfiltration. Researchers identified tools such as Chisel, Ligolo-ng, and Impacket being used to compromise Active Directory environments. Qilin’s Python scripts also contained structural patterns and comments strongly resembling LLM-generated code.

Mitigation

Organizations should prioritize securing internet-facing assets such as VPNs and remote desktop services through timely patching and MFA. Strict access controls and network segmentation can help limit lateral movement across compromised environments. Security teams should also monitor unusual administrative activity and disable unnecessary services to reduce the available attack surface.

Response

If ransomware activity is detected, affected hosts should be isolated immediately to prevent additional lateral movement and data exfiltration. Responders should review connection logs and authentication records to determine the scope of compromised credentials. EDR tools should also be used to identify large-scale file modifications and suspicious remote access activity.

Click Here For The Original Source.

——————————————————–

……….

.

.





Source link

...........