news.mlab.sh
Back to the feed
ransomware

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

CriticalCVSS 10.0
Summary

Ransomware attacks targeting Japanese businesses increased by approximately 4.7% in the first half of 2026, driven primarily by the activity of The Gentlemen ransomware group. The Gentlemen, leveraging a RaaS model and utilizing AI for operational efficiency, has significantly increased its leak site activity and is employing a double-extortion strategy. Investigation into The Gentlemen’s infrastructure revealed a sophisticated attack flow, utilizing tools like RustHound, Chisel, and Ligolo-ng to establish network routes, conduct reconnaissance, exploit vulnerabilities (including CVE-2025-2479 and MS17-010), and exfiltrate data via VHDX backups. The group also utilizes the AdaptixC2 framework for C2 operations and employs a deletion strategy to remove traces of their activity.

Ransomware incidents in Japan rose slightly in the first half of 2026, with a total of 90 organizations affected, representing a 4.7% increase compared to the same period last year. The Gentlemen ransomware group was the most active, significantly increasing its presence on its leak site, with a 2.2-fold increase in listings from January to July. The group is utilizing a double-extortion strategy, encrypting data and threatening to publish stolen information. Russian-speaking individuals are suspected to be involved in The Gentlemen’s operations.

Qilin, another prominent ransomware group, is leveraging AI to improve its operational efficiency.

**Victimized Companies:** Cisco Talos identified 90 Japanese companies affected by ransomware between January and July 2026. The manufacturing sector accounted for 34% of incidents, followed by professional, scientific, and technical services (16%) and wholesale trade (13%). Organizations with capital of less than JPY 100 million accounted for 78% of the total incidents, indicating a focus on smaller businesses.

**Investigation of The Gentlemen’s Open Directory Infrastructure:** Talos identified open directory infrastructure used by The Gentlemen. The group employs a range of tools to support its operations, including: RustHound (for Active Directory information collection), CVE-2025-2479 (SQL injection in GLPI), Responder, Impacket, Ligolo-ng, Chisel, AnyDesk, Rclone, and AdaptixC2.

**Attack Flow:** The Gentlemen’s attack flow can be broken down into six phases:

1. **Phase 1:** Establishing Network Routes – Utilizing VPN software (Chisel, Ligolo-ng) and pivoting tools to create attack platforms. 2. **Phase 2:** Target Reconnaissance – Employing nmap and Masscan to assess publicly exposed hosts, VPN ports, web services, SMB, and other active services. 3. **Phase 3:** Vulnerability Exploitation – Exploiting vulnerabilities like CVE-2025-2479 (SQL injection in GLPI) and MS17-010 to gain access to systems. 4. **Phase 4:** Lateral Movement & Credential Collection – Leveraging information from Phase 3 to move within the internal network and Active Directory, collecting credentials and attempting authentication to services like SMB, LDAP, and RDP. 5. **Phase 5:** Data Exfiltration – Transferring VHDX backups via Rclone, compressing them with zstd, and splitting them into chunks for faster transfer. 6. **Phase 6:** Cleanup – Deleting credential dumps, scan results, and other tools to remove traces of activity.

The Gentlemen utilizes AdaptixC2 for C2 operations, a post-exploitation framework designed for penetration testing, but potentially used in real-world attacks.

**Why it Matters:** The increase in ransomware activity, coupled with the sophisticated techniques employed by groups like The Gentlemen and Qilin, highlights the growing threat landscape for Japanese businesses. The focus on smaller enterprises underscores the need for enhanced security measures and proactive threat detection for organizations of all sizes.

Read the full article at Cisco Talos