Warning: Organizations Need to Prep For AI-Powered Ransomware Attacks

Stu Sjouwerman | Feb 6, 2025

Ransomware Attaacks on UK OrganizationsThe rise of agentic AI tools will transform the cybercrime landscape, according to a new report from Malwarebytes.

Agentic AI—which is still under development—is a step above the generative AI tools that are currently available to the public, and will likely be widely released in 2025. While these tools will have many legitimate uses, they’ll also enable cybercriminals to scale their attacks.

“Emerging agentic AI models—which can reason, plan, and act autonomously—will further revolutionize cybercriminal tactics, making attacks more scalable and efficient in 2025,” the researchers write. “Just as businesses are beginning to explore AI for productivity and security, cybercriminals are leveraging it to improve phishing campaigns, evade detection, and fine-tune attacks.

This marks a turning point: the arms race between AI-powered attackers and AI-enhanced cybersecurity tools is rapidly escalating, forcing businesses to rethink traditional defense strategies.”

Notably, agentic AI could enable attackers to automate big-game ransomware attacks, which currently require a great deal of effort.

“Agentic AI could be used to scale up the number and speed of attacks,” Malwarebytes says. “Big game ransomware requires a lot of human labor. With the expected near-term advances in AI, we could soon live in a world where well-funded ransomware gangs use AI agents to attack multiple targets at the same time. Malicious AI agents might also be tasked with searching out and compromising vulnerable targets, running and fine-tuning malvertising campaigns, or determining the best method for breaching victims.”

The researchers add that 2024 was “the worst year ever for big game ransomware,” with a 13% increase in these attacks compared to 2023.

New-school security awareness training can enable your employees to stay ahead of evolving security threats. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Malwarebytes has the story.

Ransomware Simulator

Free downloadable software tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the installer and run it
  • Results in a few minutes!

Get RanSim!

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.