{"id":6058,"date":"2025-08-28T04:46:57","date_gmt":"2025-08-28T04:46:57","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=6058"},"modified":"2025-08-28T04:46:58","modified_gmt":"2025-08-28T04:46:58","slug":"first-recognized-ai-powered-ransomware-uncovered-by-eset-analysis","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=6058","title":{"rendered":"First recognized AI-powered ransomware uncovered by ESET Analysis"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">The invention of PromptLock reveals how malicious use of AI fashions might supercharge ransomware and different threats<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/anton-cherepanov\/\" title=\"Anton Cherepanov\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2020\/03\/Anton_Cherepanov.jpg\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2020\/03\/Anton_Cherepanov.jpg\" alt=\"Anton Cherepanov\"\/><\/picture><\/a><\/div>\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/peter-strycek\/\" title=\"Peter Str\u00fd\u010dek\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2024\/11-2024\/eset-research.png\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2024\/11-2024\/eset-research.png\" alt=\"Peter Str\u00fd\u010dek\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>26 Aug 2025<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>2 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2025\/08-25\/ai-powered-ransomware.jpeg\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2025\/08-25\/ai-powered-ransomware.jpeg\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2025\/08-25\/ai-powered-ransomware.jpeg\" alt=\"First known AI-powered ransomware uncovered by ESET Research\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p>ESET researchers have found what they known as &#8220;the primary recognized AI-powered ransomware&#8221;. The malware, which ESET has named PromptLock, has the power to exfiltrate, encrypt and presumably even destroy knowledge, although this final performance seems to not have been applied within the malware but.<\/p>\n<p>Whereas PromptLock was not noticed in precise assaults and is as a substitute considered a proof-of-concept (PoC) or a piece in progress, ESET&#8217;s discovery reveals how malicious use of publicly-available AI instruments might supercharge ransomware and different pervasive cyberthreats.<\/p>\n<blockquote class=\"twitter-tweet\"><p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/twitter.com\/ESETresearch\/status\/1960365364300087724\" target=\"_blank\"\/><\/p><\/blockquote>\n<p>\u201cThe PromptLock malware makes use of the gpt-oss-20b mannequin from OpenAI domestically by way of the Ollama API to generate malicious Lua scripts on the fly, which it then executes. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the native filesystem, examine goal information, exfiltrate chosen knowledge, and carry out encryption,&#8221; <a rel=\"nofollow\" target=\"_blank\" name=\"OLE_LINK5\"\/>stated ESET researchers.<\/p>\n<p>&#8220;The PromptLock ransomware is written in Golang, and we&#8217;ve got recognized each Home windows and Linux variants uploaded to VirusTotal,&#8221; added the researchers. Golang is a extremely versatile, cross-platform programming language that has additionally gained recognition amongst malware authors in recent times.<\/p>\n<h3>Certain to occur<\/h3>\n<p>AI fashions have made it kid&#8217;s play to craft convincing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2023\/02\/22\/chatgpt-level-up-phishing-defenses\/\">phishing messages<\/a>, in addition to deepfake <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/ai-driven-deception-new-face-corporate-fraud\/\">photos<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/your-voice-is-my-password\/\">audio<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/ai-driven-identify-fraud-havoc\/\">video<\/a>. The prepared availability of those instruments additionally drastically lowers the barrier to entry for much less tech-savvy attackers, permitting them to punch above their weight.<\/p>\n<p>In the meantime, the ransomware scourge has, through the years, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/business-security\/resilience-face-ransomware-key-business-survival\/\">examined the cyber-mettle<\/a> of numerous organizations, with such a malware additionally <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/business-security\/state-aligned-apt-groups-increasingly-deploying-ransomware\/\">more and more deployed by APT teams<\/a>. As AI is already <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ncsc.gov.uk\/report\/impact-of-ai-on-cyber-threat\">utilized by all sorts of menace actors<\/a> to various levels, it is also set to assist energy a rise within the quantity and affect of ransomware assaults.<\/p>\n<p>Whatever the intent behind PromptLock, its discovery factors to how AI instruments can be utilized to automate varied levels of ransomware assaults, from reconnaissance to knowledge exfiltration, at a velocity and scale as soon as thought not possible. The prospect of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2023\/02\/20\/will-chatgpt-start-writing-killer-malware\/\">AI-powered malware<\/a> that may, amongst different issues, adapt to the setting and alter its ways on the fly might typically characterize a brand new frontier in cyberattacks.<\/p>\n<\/div>\n<p><template id="Ol9tdXjGyA2W5rO5k63R"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The invention of PromptLock reveals how malicious use of AI fashions might supercharge ransomware and different threats 26 Aug 2025 \u00a0\u2022\u00a0 , 2 min. learn ESET researchers have found what they known as &#8220;the primary recognized AI-powered ransomware&#8221;. The malware, which ESET has named PromptLock, has the power to exfiltrate, encrypt and presumably even destroy [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6060,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1390,679,500,193,2238],"class_list":["post-6058","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-aipowered","tag-eset","tag-ransomware","tag-research","tag-uncovered"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6058","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6058"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6058\/revisions"}],"predecessor-version":[{"id":6059,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6058\/revisions\/6059"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/6060"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6058"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6058"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6058"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 08:26:09 UTC -->