HomeSecurityPromptLock: The first AI-powered ransomware

PromptLock: The first AI-powered ransomware

Cybersecurity firm ESET has discovered a new ransomware variant powered by artificial intelligence (AI) and codenamed PromptLock.

PromptLock AI ransomware

Written in Golang, the new ransomware uses OpenAI's gpt-oss:20b model locally, via the Ollama API, to generate malicious Lua scripts in real time. The model was open-sourced and released by OpenAI earlier this month.

PromptLock leverages Lua scripts, generated from predefined commands, to scan the local file system, inspect targeted files, extract selected data, and perform encryption ,” ESET said . “ These Lua scripts are cross-platform, running on Windows, Linux, and macOS .”

The ransomware code also includes instructions to create a custom note based on the “affected files.” The infected system could be a personal computer, a corporate server, or a power distribution controller. It is currently unknown who is behind the malware, but ESET says that the PromptLock files were uploaded to VirusTotal from the United States (on August 25, 2025).

See also: Beware! New Sni5Gect attack targets 5G network

PromptLock: New ransomware with AI help

PromptLock uses AI-generated, which means that indicators of compromise (IoCs) can vary between executions,” the cybersecurity firm noted. “This variability introduces challenges to detection. If implemented properly, such an approach could significantly complicate threat identification and make defenders’ jobs more difficult.”

Researchers see the new ransomware more as a proof-of-concept (PoC) rather than fully functional malware (at least at this time).

PromptLock: The first AI-powered ransomware

PromptLock uses the 128-bit SPECK to lock files. In addition to encryption, analysis suggests that the ransomware could also be used to extract data or even destroy it, although the latter does not appear to work yet.

PromptLock does not download the entire model, which could be several gigabytes in size,” ESET explained. “Instead, the attacker can simply create a proxy or tunnel from the compromised network to a server running the Ollama API with the gpt-oss-20b model.”

See also: New Zip Slip Vulnerability: Exploited When Unzipping Files

AI at the disposal of cybercriminals

The emergence of PromptLock ransomware is yet another sign that AI is making it easier for cybercriminals, even those without technical expertise, to quickly create new campaigns, deploy malware, and create convincing phishing content and malicious websites.

Yesterday, Anthropic revealed that it had blocked accounts created by two different malicious actors. They were using the AI ​​chatbot Claude to commit identity theft and extortion, targeting at least 17 different organizations. They also developed several ransomware variants with advanced evasion, encryption, and data anti-recovery mechanisms.

This development comes as large language models (LLMs), which underpin various chatbots and AI-focused developer tools, have been found vulnerable to prompt injection attacks, potentially allowing information disclosure, data extraction and code execution.

See also: MixShell malware distributed via Contact Forms

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

PromptLock: The first AI-powered ransomware

Despite incorporating strong security and protection measures to prevent unwanted behavior, AI models have repeatedly fallen victim to new variants of injections and jailbreaks, highlighting the complexity and evolving nature of the security challenge.

Prompt injection attacks can cause AI to delete files, steal data, or perform financial transactions,” Anthropic said. “New forms of prompt injection attacks are constantly being developed by malicious actors.”

New research has uncovered a simple but clever attack called PROMISQROUTE – short for “Prompt-based Router Open-Mode Manipulation Induced via SSRF-like Queries, Reconfiguring Operations Using Trust Evasion” – that exploits ChatGPT to trigger a degradation and cause the user’s command to be sent to an older, less secure model (thus allowing the system to bypass security filters and produce unwanted results).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS