talos · Crawled Sep 18, 2026
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
1 IoCs 2 Malware 2 CVEs
Read original article ↗
AI Summary
In the first half of 2026, ransomware incidents in Japan increased slightly by 4.7%, with The Gentlemen emerging as the most active group, responsible for 14 incidents. The group operates via a Ransomware-as-a-Service (RaaS) model and uses a double-extortion tactic, leveraging infrastructure including AdaptixC2 for command-and-control. Evidence from Russian-language artifacts in scripts and bash history suggests Russian-speaking actors are involved. Qilin, the second most active group, showed signs of using generative AI in developing attack scripts, with code exhibiting structured, LLM-like patterns in tools for deploying ransomware and wiping backups.
AI-extracted · verify before operational use
Extracted Entities 4 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | AdaptixC2 | Details → |
MITRE ATT&CK TTPs 96 techniques
T1003 OS Credential Dumping · Credential Access T1012 Query Registry · Discovery T1016 System Network Configuration Discovery · Discovery T1018 Remote System Discovery · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1033 System Owner/User Discovery · Discovery T1040 Network Sniffing · Credential Access T1046 Network Service Discovery · Discovery T1047 Windows Management Instrumentation · Execution T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053 Scheduled Task/Job · Execution T1055 Process Injection · Defense Evasion T1057 Process Discovery · Discovery T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1075 T1075 T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1081 T1081 T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1086 T1086 T1087 Account Discovery · Discovery T1087.002 Domain Account · Discovery T1089 T1089 T1090 Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1110.003 Password Spraying · Credential Access T1112 Modify Registry · Defense Evasion T1120 Peripheral Device Discovery · Discovery T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1176 Browser Extensions · Persistence T1189 Drive-by Compromise · Initial Access T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1211 Exploitation for Defense Evasion · Defense Evasion T1212 Exploitation for Credential Access · Credential Access T1218 System Binary Proxy Execution · Defense Evasion T1222 File and Directory Permissions Modification · Defense Evasion T1222.001 Windows File and Directory Permissions Modification · Defense Evasion T1482 Domain Trust Discovery · Discovery T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1489 Service Stop · Impact T1490 Inhibit System Recovery · Impact T1495 Firmware Corruption · Impact T1534 Internal Spearphishing · Lateral Movement T1537 Transfer Data to Cloud Account · Exfiltration T1542.001 System Firmware · Persistence T1543.003 Windows Service · Persistence T1547.001 Registry Run Keys / Startup Folder · Persistence T1548.002 Bypass User Account Control · Privilege Escalation T1550 Use Alternate Authentication Material · Defense Evasion T1552.001 Credentials In Files · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1562.001 Disable or Modify Tools · Defense Evasion T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access T1569 System Services · Execution T1570 Lateral Tool Transfer · Lateral Movement T1573 Encrypted Channel · Command And Control T1574.002 DLL Side-Loading · Persistence T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1589 Gather Victim Identity Information · Reconnaissance T1595 Active Scanning · Reconnaissance T1599 Network Boundary Bridging · Defense Evasion T1650 Acquire Access · Resource Development T1003.001 LSASS Memory · Credential Access T1006 Direct Volume Access · Defense Evasion T1014 Rootkit · Defense Evasion T1053.005 Scheduled Task · Execution T1055.015 ListPlanting · Defense Evasion T1056.001 Keylogging · Collection T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1114 Email Collection · Collection T1204.002 Malicious File · Execution T1496 Resource Hijacking · Impact T1555 Credentials from Password Stores · Credential Access