Cisco Talos identified 90 Japanese organisations affected by ransomware between January and July 2026, with manufacturing the leading target and smaller businesses heavily affected. Researchers also found signs that Qilin-linked attack scripts may have been developed using AI-assisted coding tools.

Japan Ransomware Activity Rises as Qilin Shows Signs of AI-Generated Tools

The420 Correspondent
6 Min Read

New Delhi. Japan witnessed a rise in ransomware attacks during the first half of 2026, with confirmed incidents increasing by around 4.7% compared with the same period last year. A total of 90 confirmed cases affecting Japanese organisations were reported between January and July. Small and medium-sized businesses were the most affected, with 78% of victim companies having capital of less than 1 billion Japanese yen, while 48% had capital below 100 million yen. The manufacturing sector accounted for 34% of all incidents, making it the most targeted industry.

The change in the ransomware landscape was visible not only in the number of attacks but also in the techniques used by attackers. The Gentlemen ransomware group emerged as the most active group targeting Japan, with 14 confirmed cases. Qilin and SafePay followed with seven cases each. Gentlemen operated through a ransomware-as-a-service model, providing ready-made toolkits to affiliates, while investigations into Qilin-linked incidents uncovered Python scripts showing indications of having been developed with the assistance of large language models, or AI.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Gentlemen attacks involved the use of double-extortion tactics. Under this method, attackers first encrypt the victim’s data and then threaten to publish stolen information if the ransom is not paid. Initial access was linked to targeting remote access services such as VPNs, with tunnelling tools including Chisel and Ligolo-ng reportedly used during the attacks. Tools such as nmap and masscan were also used to scan networks and gather information about systems and resources.

Investigators also found the use of BloodHound and NetExec to collect Active Directory-related information and move laterally within networks. Responder was linked to adversary-in-the-middle activity, while impacket-partial-mic showed indications of NTLM relay techniques. The group also exploited an SQL injection vulnerability, CVE-2025-24799, in GLPI to attempt privilege escalation and further movement through networks. AnyDesk was used to maintain remote access, while Rclone was used to transfer stolen data to cloud storage.

Attackers used command-and-control tools such as AdaptixC2, Chisel and Ligolo-ng to maintain control over compromised networks. During the final stages of attacks, investigators observed activities aimed at encrypting data, disrupting recovery and removing traces of malicious activity. Russian-language comments in recovered scripts and shell histories, along with references to a Russian keyboard layout, led investigators to assess that operators associated with Gentlemen may be Russian-speaking.

The role of AI in Qilin-linked attacks has drawn particular attention from cybersecurity researchers. Investigators recovered Python scripts named deadman.py, veeam_kill.py and deploy_locker.py. The scripts contained documentation-style comments and step-by-step logging, while a reference to a directory named “llm_chatbot” was found in the bash history. The deadman.py script was designed to deliver a wiper payload through Active Directory Group Policy Objects. The purpose of veeam_kill.py was to stop Veeam backup agents, while deploy_locker.py was associated with ransomware deployment.

The analysis suggests that AI-assisted coding tools could enable attackers to recreate scripts with similar capabilities more quickly. This could make it increasingly difficult for organisations to rely solely on traditional signature-based security measures. Monitoring for unusual behaviour—including unauthorised changes to Group Policy, unexpected shutdowns of backup agents, abnormal Active Directory activity and large-scale transfers of data to cloud storage—has therefore become increasingly important.

After manufacturing, the information and communications sector accounted for 11% of incidents, followed by the services sector at 9%. Around 13.3% of cases also affected overseas offices or subsidiaries of Japanese organisations. Taiwan, the United States and the Philippines were among the locations where related foreign entities were affected.

Between January and July, the number of victims listed on the Gentlemen group’s leak site increased from 48 to 105. The rise points to a significant expansion in the group’s activity during the period. Meanwhile, Qilin’s use of AI-assisted tools indicates that ransomware operations are increasingly relying not only on ready-made malware but also on customised tools capable of automating different stages of an attack.

Organisations are being advised to review unnecessary internet-facing systems, particularly VPN and remote desktop services, implement multi-factor authentication for administrative accounts and apply critical security updates promptly. Monitoring attempts to disable backup agents and unusual Group Policy changes is also important. Security controls should extend to third-party vendors, overseas offices and subsidiaries. As ransomware techniques continue to evolve, behavioural detection and rapid response capabilities are expected to play an increasingly important role in defending networks.

About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected