Evolving Threats: The Role of AI in Modern Ransomware Attacks

Evolving Threats: The Role of AI in Modern Ransomware Attacks

🎙 Mari DeGrazia 👥 70K 📅 September 17, 2025 ⏱ 33 min 👁 453 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

AIRansomwarePhishingLLMHealthcare

Summary

Mari DeGrazia, a cybersecurity consultant and SANS instructor, presents a talk from the 2025 SANS Healthcare Forum on how AI is being leveraged in modern ransomware attacks. She begins by highlighting the heightened threat to healthcare, citing FBI reports and statistics showing that 67% of healthcare organizations will experience a ransomware attack. She then walks through the ransomware lifecycle, focusing on initial access, lateral movement, privilege escalation, data exfiltration, encryption, and extortion/negotiation. For each phase, she explains how AI, particularly large language models (LLMs), is used by threat actors. She discusses AI-generated phishing emails, which are more personalized and effective, and mentions uncensored models like WormGPT and FraudGPT. She demonstrates a live example using DeepSeek to craft a phishing email in under two minutes. She also covers AI-assisted coding, known as ‘vibe hacking,’ and cites an Anthropic report showing attackers using Claude Code to develop malware and automate attacks. She introduces ‘PromptLock,’ a proof-of-concept AI ransomware that writes its own attack code in real time. Finally, she discusses AI-powered negotiation chatbots used by ransomware groups like the Global Group, and provides defensive recommendations, emphasizing MFA, email authentication, and using AI to fight AI.

193 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable, up-to-date insights into the practical use of AI in ransomware attacks, supported by real-world examples and recent reports. The speaker’s hands-on experience adds credibility. The argumentation is logical and well-structured, walking through the attack lifecycle. However, some claims lack specific citations, and the presentation is more anecdotal than systematic.

Scientific Rigor, Source Quality, Title Accuracy

The speaker cites several reports (FBI, IBM, Anthropic) and mentions specific tools and models, but does not provide direct URLs. The title accurately reflects the content. The talk is based on expert opinion and practical experience rather than peer-reviewed research, but it is consistent with current industry knowledge.

116 words

Title / Content Match

The title accurately reflects the content, which focuses on the evolving role of AI in ransomware attacks.

Quality & Reliability

7/10

The speaker is a director at a cybersecurity consulting firm with extensive hands-on experience in ransomware response, and she is a SANS instructor. She cites specific reports (FBI, IBM, Anthropic) and provides concrete examples. However, some statistics lack direct citations, and the presentation is largely anecdotal and based on personal experience.

Key Moments

Cited Sources

Concurring Sources

  • SANS Institute — The talk is from a SANS event, and the speaker is a SANS instructor.

Contribution & Novelties

This talk provides a current, practitioner-focused overview of AI’s role in ransomware, highlighting recent developments like PromptLock and AI-powered negotiation chatbots. It offers practical insights for defenders.

Pour aller plus loin :

77 words

Radar Profile

The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-informed presentation that is accessible to a broad audience, though it relies more on expert opinion than on formal research.

Reliability 7/10