New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
blog

Ransomware Groups Are Vibe-Coding Their Way Past Old Defenses

Published

Aug 19, 2026

Introduction

I spent time at Black Hat this year fielding the same question in different phrasing: Has AI actually changed ransomware, or just changed how people talk about it? After a year of watching the Black Kite Research Group™ trace this across real cases, my read is that AI has made a narrow set of ransomware tasks a lot cheaper to run, and that shift matters more than either side of that debate gives it credit for.

Buying a Kit Is Now the Slow Way In

For years, the barrier to running a ransomware operation was technical. You needed an encryptor that actually worked, evaded EDR, and didn’t corrupt the files it was supposed to hold hostage. That’s the part that just moved. FunkSec, one of the groups our research team has been tracking, shipped encryptor code that looked more polished than the operator’s own apparent skill level would suggest. It’s one data point, not a model for the future, but it shows the direction of travel.

Sysdig researchers went further with JADEPUFFER, what they describe as the first fully agentic ransomware operation: an AI agent running reconnaissance through database encryption largely on its own, adapting to failures with limited visible human direction. I keep coming back to something Jacob Klein, Anthropic’s head of threat intelligence, said at a summit earlier this year: advanced persistent threats went from using AI as a basic chatbot in May to running 80% automated, 20% manual attack chains by September. Ransomware crews are tracking the same curve, just starting from a lower skill floor. A crew that used to need a developer on retainer now needs a laptop and a weekend.

I Ran the Recon Myself

The part that actually surprised me was recon. Mapping a company’s vendor relationships, its tech stack, and its likely dependencies used to require a paid tool like ZoomInfo, and someone who knew how to use it well. I tested this myself with an off-the-shelf AI deep-research tool, no paid subscription, no reconnaissance background beyond what I already do for a living.

It surfaced a company’s confirmed and likely third parties in a matter of minutes. Not perfectly – some entries were stale, and a couple of connections were guesses dressed up as facts. But it was accurate enough, and fast enough, that it would have shaved real hours off a reconnaissance job. Obscurity was never a real control to begin with. Now it isn’t even a speed bump.

AI Is Doing the Analyst’s Job, Not the Attacker’s

Stealer logs pile up fast, and sorting through thousands of infected endpoints to find the ones worth pursuing used to take a skilled analyst hours. That’s the work shifting fastest. TITAN AI Team, a ransomware group, now markets automated stolen-data analysis, regulatory impact assessment, and ransom calculation directly to its affiliates. The specific numbers in that pitch are unverified, and I’d treat them skeptically. But the framing tells you something the numbers don’t have to: victim triage and profitability ranking are being sold as a feature, out in the open, to an affiliate audience that used to need a skilled analyst for exactly that work.

What This Means for Your Vendor Ecosystem

What’s actually shifting here is more mundane than an autonomous-AI-attack headline. The research, the triage, and the prioritization that analysts used to do by hand are getting cheaper to outsource, stage by stage. That’s a bigger deal, because it scales. Every mid-tier crew that couldn’t previously afford a skilled operator now can, more or less, by renting one from a chatbot.

This is the same argument I’ve been making since our CVE numbers came out this year: the interesting question was never the 48,000-plus vulnerabilities published, it was the roughly 800 that actually got exploited. The same logic applies here. What matters isn’t how many ransomware groups can now write code or run recon with AI. It’s which of your vendors are showing the exposure patterns that make them worth the attention, human or AI-assisted, in the first place. Black Kite’s Ransomware Susceptibility Index® (RSI™) tracks that exposure, and our Adversary Susceptibility Index™ (ASI™) maps it to the specific groups most likely to act on it.

We go through this shift in more depth in the 2026 Ransomware Report, including the six straight months where victim counts ran past 700 a month. The tools changed. The job my team and I have been doing all year, figuring out which of your vendors are actually in the crosshairs across your third-party ecosystem, didn’t.