BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ESET Discovers PromptLock: First AI-Powered Ransomware Emerges

AI-Powered PromptLock Ransomware Emerges, Showcasing Advanced Evasion and Encryption Techniques

  • Researchers at ESET identified a new AI-powered Ransomware called PromptLock.
  • PromptLock uses locally run AI models to create malicious scripts that target files across multiple operating systems.
  • The Malware generates customized ransom notes and uses strong encryption but currently appears to be a proof-of-concept.
  • AI-generated scripts in PromptLock change with each run, making the ransomware hard to detect.
  • Ongoing developments show that major AI models and tools remain vulnerable to prompt injection and security bypass attacks.

A new ransomware called PromptLock, powered by Artificial Intelligence, has been discovered by Cybersecurity company ESET. Researchers found that PromptLock uses a locally hosted AI model from OpenAI, known as gpt-oss:20b, accessed through the Ollama API. This malware is designed to generate harmful computer scripts in real time, affecting systems running Windows, Linux, or macOS.

- Advertisement -

PromptLock operates by scanning the local filesystem, choosing files to target, and then encrypting selected data. According to ESET, it also creates a custom ransom message for each victim, based on the type of machine infected and files affected. Experts say artifacts of PromptLock were submitted to VirusTotal from the United States on August 25, 2025. Details about the individuals or groups behind the ransomware remain unknown.

“PromptLock uses Lua scripts generated by AI, which means that indicators of compromise (IoCs) may vary between executions,” ESET explained. “This variability introduces challenges for detection. If properly implemented, such an approach could significantly complicate threat identification and make defenders’ tasks more difficult.” The ransomware employs the SPECK 128-bit encryption algorithm to lock files and could also be used to steal or erase data, although file deletion features have not yet been fully added.

Unlike models that require large downloads, PromptLock attackers use a tunnel or proxy connecting infected systems to a remote server with the gpt-oss-20b model running the required API. ESET assesses that PromptLock is a proof-of-concept, not fully deployed malware.

Emerging AI threats are increasing in scale and sophistication. Anthropic recently said it banned accounts controlled by two threat actors using its Claude AI chatbot to conduct theft and extortion against at least 17 organizations and to build ransomware with advanced evasion features. The growing trend includes major AI platforms, such as Amazon Q Developer, Anthropic Claude Code, AWS Kiro, Google Jules, Lenovo Lena, Microsoft GitHub Copilot, and others, being susceptible to prompt injection attacks that may allow unauthorized access or data leaks.

- Advertisement -

“Prompt injection attacks can cause AIs to delete files, steal data, or make financial transactions,” Anthropic said. New research, such as the PROMISQROUTE attack, shows it is possible to bypass AI safety measures using simple phrases like “use compatibility mode” or “fast response needed.” These findings highlight ongoing security risks as AI adoption expands.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SpaceX secures $13B ARR deal, eyes $100B year-end target

A new Hosting deal will add approximately $13 billion in annual recurring revenue starting...

Senate GOP Updated Clarity Act Targets Fake DeFi, Vote Set

Senate Republicans released an updated Clarity Act on Thursday targeting non-decentralized crypto trading protocols.The...

TSMC revenue hits record $16.3B, AI demand fuels 53% jump

TSMC reported a record August revenue of NT$514.8 billion ($16.3 billion), marking a 53.3%...

AI Leaves Banks Minutes to Fix Flaws: BIS

A BIS paper warns that AI is shortening the time banks have to repair...

US housing split: low-end sales down, luxury up on AI wealth

Compass CEO Robert Reffkin says U.S. housing market is splitting: low-end sales down 10%...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading