Ransomware Is Spreading Faster Than You Think

Recent reporting on AI and ransomware points to a practical shift rather than a dramatic one. AI is not replacing operators or running attacks on its own. What it is doing is reducing the time it takes to prepare, test and refine techniques before they are used in real environments. 

What’s changing isn’t the attack itself. It’s how quickly attackers can get to something that works. 

 

What this looks like in practice 

Research across 2025 and 2026 shows attackers using AI to support routine parts of their workflow. This includes reviewing public research, refining payloads, improving phishing content and testing techniques against common security controls. 

In a recent Sophos case, AI-assisted tooling was used to support malware development, automate elements of Active Directory discovery and test against EDR products. The activity itself was still human-led, but the preparation around it had been accelerated Sophos.

This is the key distinction. AI is not carrying out intrusions independently. It is shortening the trial-and-error loop that sits around them. 

 

Why it matters 

The impact of that change is speed. 

There has always been a gap between new techniques being published and being used in real-world attacks. AI is reducing that gap. Attackers can test and adapt faster, which means defensive controls have less time to respond. 

CrowdStrike’s reporting already shows how tight timelines are, with breakout times frequently measured in under an hour (see CrowdStrike Global Threat Report: https://www.crowdstrike.com/global-threat-report/). When preparation becomes more efficient, the window for detection and containment reduces with it. 

 

What this means for your security 

It’s also important to look beyond the ransomware payload itself. Many successful attacks still rely on compromised credentials, weak access controls and legitimate system use rather than sophisticated malware. 

Research from ESET and others shows that disrupting security tools, including EDR, is now a routine step before encryption (see ESET research: https://www.welivesecurity.com/). Combined with consistent exploitation of known vulnerabilities and exposed services, this reinforces a clear pattern. Attackers succeed by taking control of the environment, not just by delivering malicious code. 

AI fits into this by improving efficiency. It allows attackers to iterate faster, test more thoroughly and apply known techniques with less effort. 

 

Our take 

This is not about autonomous ransomware or entirely new attack models. It’s about reduced decision time. If attackers can move from planning to working tradecraft more quickly, static or untested controls become a bigger risk. The organisations that stay ahead will be the ones that understand how their security performs under pressure, not just whether it is in place.

 

How we can help

At Evolve North, we help organisations understand how their security actually performs in practice. That includes testing detection and response capabilities against real-world techniques, identifying gaps before they’re exploited, strengthening identity and Active Directory security, and providing clear, actionable insight into where improvements are needed. If you’d like to understand how your current controls would stand up to this kind of approach. Contact us at info@evolvenorth.com or call 01748 905 002.

Arrange a FREE Consultation

Want to learn more about improving your organisation's security? Our team is here to answer your questions and explain the options available. In a free consultation, we'll help you understand the services we offer and how they can support your goals. It's a simple, no-obligation way to start exploring the right approach for your business.