Ransomware operators are increasingly using large language models (LLMs) to accelerate established stages of the ransomware lifecycle—reconnaissance, phishing, data triage, and negotiation—rather than creating fundamentally new “AI ransomware.” Reporting citing SentinelOne Labs describes crews using LLMs to rapidly generate fluent, localized phishing lures and ransom communications, summarize and classify stolen documents to identify high-value leverage, and obtain step-by-step guidance for standing up infrastructure (e.g., basic loaders and C2 components). A notable enabler is the use of locally hosted/self-managed models (e.g., via Ollama) to reduce reliance on provider guardrails and increase operational flexibility, contributing to higher attack tempo, broader multilingual reach, and lower barriers to entry for less-skilled affiliates.
Extortion tactics are also evolving beyond encryption and data theft to include pressure based on regulatory and compliance exposure, with gangs threatening to report or highlight victims’ potential violations to increase coercion and urgency. This approach aligns with a broader trend of ransomware ecosystems fragmenting into many smaller crews and copycats while sharing tooling and playbooks across crimeware markets, increasing the volume of opportunistic campaigns and the likelihood that victims face both operational disruption and amplified legal/reputational risk during negotiations.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
A CSO Online news analysis reported that ransomware gangs were pressuring victims by citing potential compliance and regulatory violations as part of extortion efforts. This reflects an evolution in ransomware leverage tactics beyond simple encryption and data theft.
Analysis published in mid-January 2026 described threat actors moving toward local or self-hosted models such as Ollama to avoid provider guardrails, and breaking malicious development into benign-looking prompt fragments that are later combined offline. The same reporting pointed to early proof-of-concept tools like PromptLock and MalTerminal as signs of possible future runtime payload generation or adaptation.
SentinelOne Labs observed that ransomware and broader crimeware actors were using large language models to increase the speed, volume, and multilingual reach of phishing, ransom-note creation, data triage, and infrastructure setup. The reporting also noted a fragmented ransomware ecosystem with many smaller crews and copycats, and blurred lines between criminal and state-linked activity.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.