Article Details

Scrape Timestamp (UTC): 2025-08-26 21:26:38.548

Source: https://www.theregister.com/2025/08/26/first_aipowered_ransomware_spotted_by/

Original Article Text

Click to Toggle View

First AI-powered ransomware spotted, but it's not active – yet. Oh, look, a use case for OpenAI's gpt-oss-20b model. ESET malware researchers Anton Cherepanov and Peter Strycek have discovered what they describe as the "first known AI-powered ransomware," which they named PromptLock.  The good news, according to the duo, who detailed PromptLock in a series of social media posts and screenshots on Tuesday, is that the malware doesn't appear to be fully functional — yet. "Although multiple indicators suggest the sample is a proof-of-concept (PoC) or work-in-progress rather than fully operational malware deployed in the wild, we believe it is our responsibility to inform the cybersecurity community about such developments," Cherepanov and Strycek wrote. However, despite the lack of in-the-wild PromptLock infections, the discovery does show that AI has made cybercriminals' attack chains that much easier, and should serve as a warning to defenders. The PromptLock malware uses Open AI's gpt-oss-20b model, which is one of the two free open-weight models the company released earlier this month. It runs locally on an infected device through the Ollama API, and it generates malicious Lua scripts on the fly, likely to make detection more difficult.  "PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption," the researchers explained, adding that the Lua scripts work on Windows, Linux, and macOS machines. The malware then decides which files to search, copy, encrypt, or even destroy, based on the file type and contents. But according to the researchers, "the destruction functionality appears to be not yet implemented." PromptLock uses the SPECK 128-bit encryption algorithm to encrypt files, and the ransomware itself is written in Go. The ESET team said they've identified both Windows and Linux variants uploaded to VirusTotal.

Daily Brief Summary

MALWARE // Emergence of AI-Driven Ransomware: PromptLock's Potential Threat

ESET researchers identified PromptLock, a pioneering AI-driven ransomware leveraging OpenAI's gpt-oss-20b model, though it remains a proof-of-concept and not yet active in real-world attacks.

PromptLock operates locally via the Ollama API, generating Lua scripts to evade detection and target Windows, Linux, and macOS systems, indicating cross-platform capabilities.

The malware uses Lua scripts to enumerate files, exfiltrate data, and perform encryption with SPECK 128-bit, though file destruction features are not yet functional.

PromptLock's development illustrates the growing ease with which AI can enhance cybercriminal activities, posing new challenges for cybersecurity defenses.

Despite its current inactive status, the discovery serves as a critical alert for cybersecurity teams to prepare for AI-enhanced threats in the near future.

ESET has identified both Windows and Linux variants on VirusTotal, emphasizing the need for vigilance and proactive threat detection measures.

Organizations should consider strengthening defenses against potential AI-driven threats, ensuring robust detection and response strategies are in place.