Contributed Article: By Aras Nazarovas, a security researcher at Cybernews
researchers have discovered an exposed server belonging to an affiliate of the Gentlemen ransomware gang. Through the server, the Cybernews team gained a rare inside look at a massive AI-powered ransomware operation.
The discovery shows how AI is changing cybercrime: a single attack costs as little as $0.40–$4.00 in tokens per company, not counting the supporting infrastructure costs. “Ransomware has effectively turned into a passive revenue stream,” said Aras Nazarovas, a security researcher at Cybernews, who discovered the leaking server.
Here are the key findings:
- The exposed server contained 3.1TB of data stolen from over 30 companies.
- The brain behind the exposed ransomware operation is an AI agent. Malicious activity relies almost entirely on AI automation, with minimal human oversight.
- The AI agent can simultaneously compromise and extort multiple targets and is used at all stages of the attack, including determining ransom demands.
- The compromised companies spanned marketing, healthcare, consulting, compliance, real estate, software development, telecommunications, manufacturing, and transportation, suggesting that attacks are opportunistic.
“Most attacks start as AI prompts. The attacker simply provides the AI agent with a GitLab URL, username, and password, likely obtained from stealer logs or purchased from initial access brokers. The AI agent then adjusts and modifies the exploit scripts based on individual victim environments. After that, the threat actor only queries the AI with questions, directing it to perform criminal actions. The AI agent has direct access to attacker-defined skills for recon, exfiltration, reverse shells, as well as files,” Nazarovas explains.
The findings were responsibly reported to CERT and the police in Lithuania prior to publication, and the authorities shared the information with international partners.
You can find the full Cybernews investigation here:
https://cybernews.com/security/exposed-ransomware-server-reveals-automated-4-dollar-cyberattacks/
Opinions expressed are the author’s own and do not necessarily reflect those of Biz Tech Journals

Leave a Reply