NYU Researchers Develop AI-Powered 'Ransomware 3.0', Sparking Cybersecurity Concerns

Reviewed byNidhi Govil

6 Sources

Share

NYU researchers create an AI-powered ransomware prototype, initially mistaken for a real threat, highlighting potential risks and challenges in cybersecurity.

NYU's Groundbreaking AI Ransomware Research

Researchers at New York University's Tandon School of Engineering have developed a proof-of-concept for AI-powered ransomware, dubbed "Ransomware 3.0," which has sent ripples through the cybersecurity community

1

2

3

. This experimental malware, initially mistaken for a real-world threat, demonstrates the potential for artificial intelligence to autonomously execute complete ransomware attacks.

Source: Tom's Hardware

Source: Tom's Hardware

The PromptLock Incident

The research project gained unexpected attention when cybersecurity firm ESET discovered the malware on VirusTotal, a platform used for testing malicious files. ESET initially reported it as "PromptLock," believing it to be the first AI-powered ransomware found in the wild

1

3

. This misunderstanding highlights the sophistication of the NYU team's work, as it was convincing enough to be mistaken for a genuine threat by security experts.

Capabilities of Ransomware 3.0

The AI system developed by the NYU team can perform all four phases of a ransomware attack:

  1. Mapping systems
  2. Identifying valuable files
  3. Stealing or encrypting data
  4. Generating ransom notes

These operations were successfully tested across personal computers, enterprise servers, and industrial control systems

4

5

. The malware uses large language models to generate customized Lua scripts for each target, making it highly adaptable and potentially more difficult to detect than traditional ransomware

2

.

Economic Implications and Accessibility

Source: MediaNama

Source: MediaNama

One of the most concerning aspects of this research is its potential economic impact on cybercrime. Traditional ransomware campaigns require significant resources, including skilled developers and custom malware creation. However, the NYU prototype demonstrated that a complete attack execution could cost as little as $0.70 using commercial API services, with open-source AI models potentially eliminating costs entirely

4

5

.

Cybersecurity Challenges

The AI-generated nature of this ransomware poses significant challenges for cybersecurity defenses. Traditional security software relies on detecting known malware signatures or behavioral patterns. However, AI-generated attacks produce variable code and execution behaviors that could evade these detection systems

4

. The researchers found that their AI models were highly effective at system mapping, correctly identifying 63-96% of sensitive files depending on the environment

5

.

Source: The Register

Source: The Register

Ethical Considerations and Research Impact

The NYU team conducted their research under strict ethical guidelines within controlled laboratory environments. Their prototype is non-functional outside of the lab setting

3

4

. By publishing their findings, the researchers aim to provide critical technical details to help the cybersecurity community understand and prepare for this emerging threat model

5

.

Recommendations for Defense

To counter potential AI-powered ransomware threats, the researchers recommend:

  1. Monitoring sensitive file access patterns
  2. Controlling outbound AI service connections
  3. Developing detection capabilities specifically designed for AI-generated attack behaviors

    4

    5

As AI continues to evolve, it's clear that both cybersecurity professionals and policymakers will need to stay ahead of potential misuse by malicious actors. The NYU research serves as a crucial early warning, allowing the security community to develop countermeasures before these AI-powered techniques fall into the wrong hands.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo