About as much as the fee charged by a cash machine when you withdraw money from a bank outside your own network. That is the remarkably low price of launching a ransomware attack against a major company or public body as though you were a professional cybercriminal.
Artificial intelligence is making these threats even more accessible, putting them within reach of anyone with a few euros to spare. This is demonstrated by a discovery made by cybersecurity news outlet Cybernews.
Its research team uncovered infrastructure that enabled a complete ransomware operation to be carried out at very little cost. It hosted malicious payloads, internal exploitation tools, an AI system and data dumps spanning the entire attack lifecycle, from initial access to ransom demands.
In late July, the team discovered an exposed server containing a vast amount of data: 3.1 TB stolen from more than 30 companies. The victims operated in marketing, healthcare, consulting, regulatory compliance, property, software development, telecommunications, manufacturing and transport.
The server turned out to belong to The Gentlemen, a well-known ransomware gang that emerged in July last year and is now one of the most active groups of its kind. It is estimated to have claimed 700 victims to date.
Beyond the technical details, the most striking aspect of the discovery is the extent to which the extortion group relied almost entirely on AI-powered automation for its malicious activity, with minimal human oversight.
“Most attacks begin with prompts to the AI. The attacker simply provides the AI agent with the GitLab URL, username and password, probably obtained from infostealer logs or purchased from initial access brokers,” explained Aras Nazarovas, the Cybernews security researcher who discovered the exposed server.
“The AI agent adjusts and modifies the exploitation scripts to suit each victim’s environment,” he added.
For just a few dollars
The logs reveal the extraordinarily low cost of the entire operation. A single attack costs between $0.40 and $4 in tokens per victim, excluding the cost of the supporting infrastructure.
The key is that the Hermes agent can compromise and extort multiple targets simultaneously and is used at every stage of the attack, including to determine ransom demands. This helps make the operation so cheap for its ‘affiliates’.
But how can a ransomware group ask an AI assistant to hack a company and have it carry out the malicious task without refusing?
The Gentlemen uses a ‘trick’ to deceive the large language model (LLM) into complying with its requests. The prompt presents the task as an Alice in Wonderland-inspired Capture the Flag (CTF) cybersecurity challenge. In other words, the AI agent is misled into believing that it is solving cybersecurity exercises rather than compromising real victims.
“We found source files for an open-source CTF challenge implemented by an AI agent, as well as scripts suggesting that it was solved by an AI agent. The CTF challenge was cloned from a public GitHub repository and was originally designed to test security professionals’ skills in exploiting common GitLab CI/CD vulnerabilities and weaknesses,” Nazarovas said.
The findings were responsibly disclosed to Lithuania’s national CERT and police before publication, and the authorities shared the information with international partners.
Click Here For The Original Source.

