7 Sources
[1]
The Era of AI-Generated Ransomware Has Arrived
As cybercrime surges around the world, new research increasingly shows that ransomware is evolving as a result of widely available generative AI tools. In some cases, attackers are using AI to draft more intimidating and coercive ransom notes and conduct more effective extortion attacks. But
[2]
Mysterious 'PromptLock' Ransomware Is Harnessing OpenAI's Model
Don't miss out on our latest stories. Add PCMag as a preferred source on Google. Whether for malicious purposes or simply research, someone appears to be using OpenAI's open-source model for ransomware attacks, according to antivirus company ESET. On Tuesday, ESET said it had discovered "the
[3]
The first AI-powered ransomware has been discovered -- "PromptLock" uses local AI to foil heuristic detection and evade API tracking
Hackers finally discover a practical use for local AI models ESET today announced the discovery of "the first known AI-powered ransomware." The ransomware in question has been dubbed PromptLock, presumably because seemingly everything related to generative AI has to be prefixed with
[4]
First AI-powered ransomware PoC spotted
ESET malware researchers Anton Cherepanov and Peter Strycek have discovered what they describe as the "first known AI-powered ransomware," which they named PromptLock. The good news, according to the duo, who detailed PromptLock in a series of social media posts and screenshots on Tuesday, is that
[5]
A hacker used AI to create ransomware that evades antivirus detection
Vibe coding is all the rage among enthusiasts who are using large language models (or "AI") to replace conventional software development, so it's not shocking that vibe coding has been used to power ransomware, too. According to one security research firm, they've spotted the first example of
[6]
Warning: AI-powered ransomware is real and in the wild
As if there weren't enough privacy concerns in the world, AI ransomware is now reportedly a thing. Cybersecurity firm ESET said that it discovered the first-ever AI-powered ransomware, which it has dubbed PromptLock. "The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the
[7]
AI Meets Ransomware, The New Cyber Threat
Ransomware has long been one of the most feared cyber threats on the internet, and for good reason. It's fast, disruptive, and increasingly effective at locking up your most important files and demanding payment in exchange for their return. It's not just businesses that get hit, either. Everyday
Share
Copy Link
Researchers have discovered PromptLock, the first known AI-powered ransomware, which uses OpenAI's open-source model to generate malicious code and evade detection. This development marks a significant shift in cybercrime tactics and raises concerns about the potential misuse of AI in malware creation.
In a significant development in the cybersecurity landscape, researchers have identified what appears to be the first instance of AI-powered ransomware, dubbed "PromptLock". This discovery, made by antivirus company ESET, marks a concerning evolution in the capabilities of cybercriminals
1
.
Source: Tom's Hardware
PromptLock utilizes OpenAI's open-source model gpt-oss:20b, which can run locally on high-end desktop PCs or laptops with a 16GB GPU. The ransomware employs this model to generate malicious Lua scripts on the fly, enabling it to perform various functions such as enumerating the local filesystem, inspecting target files, exfiltrating data, and encrypting files
2
.PromptLock's architecture is designed to be cross-platform compatible, functioning on Windows, Linux, and macOS. It uses the SPECK 128-bit encryption algorithm and is written in Go
4
. The use of locally-run AI models allows the ransomware to evade detection by traditional antivirus software and avoid API tracking that could alert OpenAI to its malicious use3
.The emergence of AI-powered ransomware like PromptLock represents a significant shift in the cybercrime landscape. It demonstrates how generative AI is pushing cybercrime forward and lowering the barrier to entry for attackers, even those without extensive technical skills or ransomware experience
1
.Anthropic, another AI company, has reported that cybercriminals are increasingly using AI tools like their large language model Claude to develop, market, and distribute ransomware with advanced evasion capabilities. In some cases, these tools are being sold as services on cybercrime forums for prices ranging from $400 to $1,200
1
.
Source: Mashable
While PromptLock's discovery is concerning, researchers note that it appears to be a proof-of-concept or work-in-progress rather than fully operational malware. Some functionalities, such as file destruction, have not yet been implemented
2
.However, security experts warn that the attack is highly viable. Even though the AI model used is large (13GB), attackers can establish a proxy or tunnel from the compromised network to a server running the model, making it a practical threat
1
.Related Stories
In response to these developments, AI companies are implementing new safeguards. Anthropic, for instance, has banned accounts linked to ransomware operations and introduced new methods for detecting and preventing malware generation on its platforms
1
.
Source: PC Magazine
OpenAI, the creator of the model used in PromptLock, has stated that they take steps to reduce the risk of malicious use and are continually improving safeguards to make their models more robust against exploits
1
.The discovery of PromptLock serves as a wake-up call for the cybersecurity community. As AI technologies become more accessible, there is an increasing need for robust defense mechanisms and responsible AI development practices to mitigate the risks posed by AI-powered malware.
Summarized by
Navi
[3]
[4]
04 Sept 2025•Technology

01 Jul 2026•Technology

11 Sept 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology