Recent reporting on AI and ransomware points to a practical shift rather than a dramatic one. AI is not replacing operators or running attacks on its own. What it is doing is reducing the time it takes to prepare, test and refine techniques before they are used in real environments.
What’s changing isn’t the attack itself. It’s how quickly attackers can get to something that works.
What this looks like in practice
Research across 2025 and 2026 shows attackers using AI to support routine parts of their workflow. This includes reviewing public research, refining payloads, improving phishing content and testing techniques against common security controls.
In a recent Sophos case, AI-assisted tooling was used to support malware development, automate elements of Active Directory discovery and test against EDR products. The activity itself was still human-led, but the preparation around it had been accelerated Sophos.
This is the key distinction. AI is not carrying out intrusions independently. It is shortening the trial-and-error loop that sits around them.
Why it matters
The impact of that change is speed.
There has always been a gap between new techniques being published and being used in real-world attacks. AI is reducing that gap. Attackers can test and adapt faster, which means defensive controls have less time to respond.
CrowdStrike’s reporting already shows how tight timelines are, with breakout times frequently measured in under an hour (see CrowdStrike Global Threat Report: https://www.crowdstrike.com/global-threat-report/). When preparation becomes more efficient, the window for detection and containment reduces with it.
What this means for your security
It’s also important to look beyond the ransomware payload itself. Many successful attacks still rely on compromised credentials, weak access controls and legitimate system use rather than sophisticated malware.
Research from ESET and others shows that disrupting security tools, including EDR, is now a routine step before encryption (see ESET research: https://www.welivesecurity.com/). Combined with consistent exploitation of known vulnerabilities and exposed services, this reinforces a clear pattern. Attackers succeed by taking control of the environment, not just by delivering malicious code.
AI fits into this by improving efficiency. It allows attackers to iterate faster, test more thoroughly and apply known techniques with less effort.
Our take
This is not about autonomous ransomware or entirely new attack models. It’s about reduced decision time. If attackers can move from planning to working tradecraft more quickly, static or untested controls become a bigger risk. The organisations that stay ahead will be the ones that understand how their security performs under pressure, not just whether it is in place.
How we can help
At Evolve North, we help organisations understand how their security actually performs in practice. That includes testing detection and response capabilities against real-world techniques, identifying gaps before they’re exploited, strengthening identity and Active Directory security, and providing clear, actionable insight into where improvements are needed. If you’d like to understand how your current controls would stand up to this kind of approach. Contact us at info@evolvenorth.com or call 01748 905 002.
