Security

Ransomware Gang Uses AI Agents to Automate Attacks for Under $4

Exposed server reveals how The Gentlemen cybercrime group deploys AI to breach companies at token costs, bypassing LLM safeguards with prompt engineering tricks.

Omega Editorial· September 7, 2026· 3 min read

AI-Powered Ransomware Operations Cost Pennies Per Attack

Cybercriminals are now executing complete ransomware operations for less than the cost of an ATM withdrawal fee. Security researchers have documented a ransomware gang that relies almost entirely on AI automation to breach companies, steal data, and issue extortion demands—all for between $0.40 and $4 in API tokens per victim.

Cybersecurity outlet Cybernews discovered an exposed server in late July belonging to The Gentlemen, a ransomware group that has claimed approximately 700 victims since emerging in July 2025. The server contained 3.1 terabytes of stolen data from more than 30 companies across marketing, healthcare, consulting, telecommunications, manufacturing, and other sectors.

How the Automated Attack Chain Works

The infrastructure Cybernews uncovered revealed the full attack lifecycle, from initial compromise through ransom demands. According to Aras Nazarovas, the security researcher who made the discovery, attacks typically begin with simple prompts to an AI agent.

"The attacker simply provides the AI agent with the GitLab URL, username and password, probably obtained from infostealer logs or purchased from initial access brokers," Nazarovas explained. The AI agent then adapts exploitation scripts to match each victim's specific environment.

The group uses a system called the Hermes agent that can compromise and extort multiple targets simultaneously. This parallel processing capability, combined with minimal human oversight, drives the remarkably low per-victim cost—though that figure excludes the underlying infrastructure expenses.

Bypassing LLM Safety Controls

The operation raises questions about how cybercriminals persuade AI systems to execute malicious tasks that should violate content policies. The Gentlemen employs a prompt engineering technique that frames attacks as legitimate cybersecurity exercises.

Specifically, the group disguises malicious prompts as Alice in Wonderland-themed Capture the Flag challenges—competitive exercises commonly used to train security professionals. The AI agent is led to believe it's solving educational puzzles rather than compromising real organizations.

Nazarovas noted that the team found source files for an open-source CTF challenge cloned from a public GitHub repository, originally designed to test skills in exploiting GitLab CI/CD vulnerabilities. The ransomware operators repurposed this framework to deceive the large language model.

Why It Matters

This discovery demonstrates that AI is lowering both the cost and technical barriers to sophisticated cybercrime. Organizations can no longer assume that ransomware attacks require significant resources or expertise—threat actors with minimal investment can now automate operations that previously demanded skilled human operators. The economics of cybercrime are shifting in ways that will likely accelerate attack volumes across all sectors.

Disclosure and Response

Cybernews responsibly disclosed its findings to Lithuania's national Computer Emergency Response Team and police before publication. Lithuanian authorities subsequently shared the intelligence with international law enforcement partners.

The details were first reported by Cybernews through researcher Aras Nazarovas.

#ransomware#ai security#cybercrime automation#llm exploitation#prompt engineering#the gentlemen

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 2 min read

AI Chatbots Give Dangerous Sleep Apnea Advice in UK Study

Researchers found chatbots dismissed serious symptoms in one-third of cases, potentially discouraging patients from seeking specialist care.

Via AI Watch · Sep 7, 2026
Security· 3 min read

North Korea's Kimsuky Group Deploys AI Coding Agent in Phishing Campaign

Cybersecurity researchers have identified an AI tool generating decoy documents, marking a new phase in automated attack preparation.

Via AI Watch · Sep 7, 2026
Security· 3 min read

AI Agents Could Compress Ransomware Attacks to 10 Hours

New research shows autonomous AI tools may dramatically accelerate network infiltration, leaving defenders far less time to respond.

Via AI Watch · Sep 7, 2026