Ransomware’s AI Adoption Curve: From Marketing Claim to Operating Model
|
Listen to post:
π This audio player requires that "Preferences" cookies be accepted
|
Executive summary
Somewhere in the first nine months of 2026, AI stopped being a talking point in ransomware and became part of how the work actually gets done. Tracking new ransomware-as-a-service (RaaS) launches, darknet recruitment ads and public incident reporting through this period shows a three-step progression: AI as advertising, AI as an assistant, and AI built directly into ransomware.
- AI has become a selling point. Four of eleven new ransomware operations tracked this year advertise AI capabilities to prospective affiliates. Dark-web posts about criminal AI tooling are surging from dozens a month in 2025 to hundreds a month in 2026.
- Hyflock is the clearest example of the shift. This RaaS operation pairs an unusually fast file encryptor with a language model that acts as a control layer over compromised machines.
- Real operational use is documented. One affiliate ran a commercial coding assistant interactively during live intrusions against at least eight organizations. A separate case saw 600+ attack actions executed autonomously, with no human involved.
- The real change isn’t sophistication. It’s access. AI is lowering the skill required to run a competent attack and compressing the time it takes.
How ransomware used to work
A 2021-era ransomware attack had an almost βstandardizedβ pattern. An affiliate bought network access from a broker or phished their way in, then spent days or weeks on manual reconnaissance: mapping the corporate directory, hunting for saved credentials, working out which file servers held anything worth stealing, and figuring out how to disable the antivirus before deploying the encryptor. Every one of those steps required a person who knew what they were doing, and that person could only be in one place at a time.
Negotiation was just as manual. Victims got a chat portal, and behind it sat a human working limited hours in one time zone, frequently with English not being their native language, and only a rough sense of what the stolen data was worth. Ransom demands were often guesses.
That model had natural brakes on it. Talent was scarce, attention was finite, and each additional victim consumed operator hours. Those brakes are now coming off, one at a time, and at a very fast pace.
2026 Cato CTRLβ’ Threat Report | Download the reportStage one: AI as a sales pitch
The first and least meaningful use of AI in ransomware was for marketing. New RaaS platforms have started listing AI features in what seemed like FOMO tactics. Storm describes itself as the first AI-powered, quantum-resistant ransomware. TITAN’s recruitment ad offers proprietary AI-powered stolen-data analysis tools. Nova announced an AI assistant on its leak site.
Treat these with skepticism. External research could not confirm Nova’s assistant exists at all, the only independently verified AI negotiation chatbot in the ecosystem belongs to a different group, GLOBAL GROUP, which uses it to handle victim intake and apply psychological pressure around the clock across time zones.
What matters here isn’t whether each claim is true. It’s that AI has become a competitive differentiator in a criminal marketplace. Affiliates are shopping for it, so operators are advertising it.
Stage two: AI as an assistant to a human intruder
The next step is real and documented. In one series of intrusions this year, an affiliate of a group called The Gentlemen used a commercial AI coding assistant interactively while inside victim networks. Targets included an Australian energy utility and several US manufacturers (as well as several other countries), across at least eight organizations.
The operator didn’t use the AI to write malware in advance. They used it live, as a consultant sitting next to them: running shell commands, manipulating a firewall’s VPN and directory configuration, recovering a service account password, mapping the network, ranking databases by how valuable their contents looked, staging data for theft, and creating hidden backdoor accounts for later. The affiliate deliberately chose an older model version with weaker safety controls.
Each of those tasks used to require its own specialist knowledge. Ranking a hundred databases by extortion value is a judgement call that once took an experienced operator hours. Now it takes a prompt.
Stage three: AI built into ransomware
This is where Hyflock comes in, and it’s the most significant development of the year.
Hyflock is a RaaS operation that surfaced on a darknet forum in mid-2026. The encryptor itself is written in Rust, it prioritizes database files, hunts down network shares, spreads across a Windows domain through Group Policy, deletes backup shadow copies, dismantles Windows Defender in stages, pauses 27 different cloud sync services so it can encrypt cloud-backed files, then wipes its own traces. Its operators claim it runs two to three times faster than LockBit 3.0 on comparable hardware.
But the encryptor is not the interesting part. The interesting part is what Hyflock ships alongside it: a command-and-control platform driven by a large language model.
According to the operators, the AI agent can interact with compromised Windows machines through a live shell and file browser, hunt for credentials and sensitive data on its own, analyze what it finds, manage multiple victims, accept operator-supplied tools as plug-ins it then knows how to use, and assist with privilege escalation and evading security products. It can also sort stolen data into categories and help draft extortion material tailored to that victim. Read that list again with the 2021 attack in mind. It covers nearly the entire span of work that used to demand a skilled human.
These are the operators’ own claims are still to be confirmed by potential buyers. But the direction the market is going is unmistakable. Hyflock is not selling AI as a chatbot bolted onto a leak site. It is selling AI as the orchestration layer of the attack, packaged so that a less capable affiliate can operate at the level of a proffesional one.
What actually changes: speed, scale, and who
Three things are shifting at once.
Speed. Reconnaissance and lateral movement that used to take days now compresses into hours. Detection windows that assumed human pace are being invalidated.
Scale. A human operator works one intrusion at a time. An AI-driven C2 platform can supervise many at once and handle first contact with every victim simultaneously, in their own language and time zone. A hybrid model is becoming standard, where AI handles intake and humans step in only when the numbers get large.
Who. This is the one that worries me the most. Criminal AI services now sell for less than a streaming subscription. An uncensored model that generates ransomware and credential stealers goes for $8 a month. A self-hosted service that takes a single domain name and produces a full attack plan goes for $100 a month. On the industrial side, a government advisory this August confirmed attackers using AI-generated scripts, disguised as legitimate monitoring tools, to read and write the memory of industrial controllers. As one OT security firm put it, the barrier to entry for attacking internet-exposed industrial systems has never been lower.
The skill shortage that used to constrain ransomware volume is being dissolved by a subscription.
What this means for defenders
Two practical shifts follow.
AI-assisted intrusions leave distinctive fingerprints. Both the autonomous case and the assistant-driven case produced verbose per-action code comments, natural-language reasoning left sitting inside scripts, rapid self-correction patterns, and outbound connections to AI provider endpoints from processes that have no business making them. Unexpected traffic to model APIs from a non-browser process on a server is now a meaningful signal.
And the fundamentals matter more, not less. Hyflock’s encryptor spends most of its effort on deleting shadow copies, disabling tamper protection, and reaching network shares. Immutable offline backups, tested restore procedures, alerting on backup deletion, and fast patching of internet-facing services will make all of the difference. AI has changed who can run the attack and how quickly. It has not yet changed what stops it. The marketing is still ahead of the capability. But the gap is closing, and it is closing in the direction of putting skilled attacks in unskilled hands.



