Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload.
Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
The first documented fully agentic AI ransomware attack chain was recorded in July 2026. The incident was attributed in the report to JadePuffer.
ExfilSquad claimed to have stolen 570,000 records from Analog Devices following an alleged July incident. The claim was not verified.
Coca-Cola subsidiary Fairlife suffered a ransomware attack in July that was thought to be the work of Anubis. The group claimed it stole more than 1 TB of data.
EY experienced a July data breach that exposed client information and tax records. ShinyHunters claimed responsibility for the incident.
The ransomware-as-a-service operation CRPxO emerged in July 2026 and quickly claimed 36 organizational compromises. NCC Group assessed the claims as low-to-moderate credibility because the group had not released datasets or obtained victim confirmation and presented inconsistent evidence.
NCC Group recorded 894 ransomware victim-organization listings in July 2026, a year-to-date monthly high and a 22% increase from June. The industrial sector represented nearly one-third of recorded incidents, while U.S. organizations accounted for 41% of listings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.