6 Sources
[1]
AI-powered PromptLocker ransomware is just an NYU research project -- the code worked as a typical ransomware, selecting targets, exfiltrating selected data and encrypting volumes
ESET said on Aug. 26 that it had discovered the first AI-powered ransomware, which it dubbed PromptLocker, in the wild. But it seems that wasn't the case: New York University (NYU) researchers have claimed responsibility for the malware ESET found. It turns out PromptLocker is actually an
[2]
Here's how ransomware crims are abusing AI tools
AI-powered ransomware, extortion chatbots, vibe hacking ... just wait until agents replace affiliates It's no secret that AI tools make it easier for cybercriminals to steal sensitive data and then extort victim organizations. But two recent developments illustrate exactly how much LLMs lower the
[3]
The crazy, true story behind the first AI-powered ransomware
Within a week, however, it nearly set the security industry on fire over what was believed to be the first-ever AI-powered ransomware. A group of New York University engineers who had been studying the newest, most sophisticated ransomware strains along with advances in large language models and
[4]
Large language models can execute complete ransomware attacks autonomously, research shows
Criminals can use artificial intelligence, specifically large language models, to autonomously carry out ransomware attacks that steal personal files and demand payment, handling every step from breaking into computer systems to writing threatening messages to victims, according to new research
[5]
Large Language Models Can Execute Complete Ransomware Attacks Autonomously, NYU Tandon Research Shows | Newswise
Newswise -- Criminals can use artificial intelligence, specifically large language models, to autonomously carry out ransomware attacks that steal personal files and demand payment, handling every step from breaking into computer systems to writing threatening messages to victims, according to new
[6]
What Does AI-Assisted Hacking Mean For Cybersecurity?
A recent threat intelligence report from Anthropic revealed the emergence of "vibe-hacking", where cybercriminals used AI coding agents like Claude Code to launch cyber attacks against at least 17 international targets. Vibe-hacking is a play on "vibe-coding" which refers to the use of generative
Share
Copy Link
NYU researchers create an AI-powered ransomware prototype, initially mistaken for a real threat, highlighting potential risks and challenges in cybersecurity.
Researchers at New York University's Tandon School of Engineering have developed a proof-of-concept for AI-powered ransomware, dubbed "Ransomware 3.0," which has sent ripples through the cybersecurity community
1
2
3
. This experimental malware, initially mistaken for a real-world threat, demonstrates the potential for artificial intelligence to autonomously execute complete ransomware attacks.
Source: Tom's Hardware
The research project gained unexpected attention when cybersecurity firm ESET discovered the malware on VirusTotal, a platform used for testing malicious files. ESET initially reported it as "PromptLock," believing it to be the first AI-powered ransomware found in the wild
1
3
. This misunderstanding highlights the sophistication of the NYU team's work, as it was convincing enough to be mistaken for a genuine threat by security experts.The AI system developed by the NYU team can perform all four phases of a ransomware attack:
These operations were successfully tested across personal computers, enterprise servers, and industrial control systems
4
5
. The malware uses large language models to generate customized Lua scripts for each target, making it highly adaptable and potentially more difficult to detect than traditional ransomware2
.
Source: MediaNama
One of the most concerning aspects of this research is its potential economic impact on cybercrime. Traditional ransomware campaigns require significant resources, including skilled developers and custom malware creation. However, the NYU prototype demonstrated that a complete attack execution could cost as little as $0.70 using commercial API services, with open-source AI models potentially eliminating costs entirely
4
5
.The AI-generated nature of this ransomware poses significant challenges for cybersecurity defenses. Traditional security software relies on detecting known malware signatures or behavioral patterns. However, AI-generated attacks produce variable code and execution behaviors that could evade these detection systems
4
. The researchers found that their AI models were highly effective at system mapping, correctly identifying 63-96% of sensitive files depending on the environment5
.
Source: The Register
Related Stories
The NYU team conducted their research under strict ethical guidelines within controlled laboratory environments. Their prototype is non-functional outside of the lab setting
3
4
. By publishing their findings, the researchers aim to provide critical technical details to help the cybersecurity community understand and prepare for this emerging threat model5
.To counter potential AI-powered ransomware threats, the researchers recommend:
4
5
As AI continues to evolve, it's clear that both cybersecurity professionals and policymakers will need to stay ahead of potential misuse by malicious actors. The NYU research serves as a crucial early warning, allowing the security community to develop countermeasures before these AI-powered techniques fall into the wrong hands.
Summarized by
Navi
[2]
[3]
[4]
27 Aug 2025•Technology

01 Jul 2026•Technology

30 May 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology