#PromptLock
PromptLock, dubbed "the first AI-powered ransomware," lacked persistence, lateral movement, and evasion tactics. One researcher put it bluntly: if you paid developers for this work, you'd demand a refund. Three years into the GenAI craze, threat development remains painfully slow.
November 11, 2025 at 7:40 PM
PromptLock, AI ransomware sample, is not a real ransomware sample. It was actually an academic study, it doesn't work, ESET got called out for a few months ago by me for saying it was the first AI ransomware. It's also widely detected out of box. Google mention it's a PoC, but don't give detail.
November 5, 2025 at 4:05 PM
AI-powered ransomware is here.

Researchers just uncovered PromptLock—ransomware strain that uses OpenAI’s new gpt-oss:20b model to write unique attack scripts on every run.

◉ Cross-platform: Windows, Linux, macOS.
◉ Harder to spot. Harder to stop.
◉ For now, it’s “just” a PoC. #Ransomware #AI
Someone Created First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model
ESET uncovers AI-powered PromptLock ransomware using OpenAI gpt-oss:20b model, complicating detection with variable Lua scripts.
thehackernews.com
August 27, 2025 at 9:12 PM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 5, 2025 at 11:03 PM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 7, 2025 at 11:33 AM
Hackers have a new accomplice. A newly discovered malware called "PromptLock" doesn't do the dirty work itself—it just gives a to-do list to a local AI and has the AI carry out the ransomware attack for it. #TechNews

archive.is/dzjw3
August 28, 2025 at 7:50 PM
InfoSec News Nuggets 8/27/2025 The first AI-powered ransomware has been discovered — “PromptLock” uses local AI to foil heuristic detection and evade API tracking ESET today announced the dis...

#InfoSec #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #nuggets"/hashtag/Nuggets" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Nuggets #AboutDFIR #DOGE #fcc #news #nuggets

Origin | Interest | Match
InfoSec News Nuggets 8/27/2025
aboutdfir.com
August 27, 2025 at 3:23 PM
The PromptLock ransomware is written in #Golang, and we have identified both Windows and Linux variants uploaded to VirusTotal. 6/7
August 26, 2025 at 3:38 PM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 6, 2025 at 4:32 PM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 6, 2025 at 5:33 PM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 7, 2025 at 3:03 AM
🚨 NEW VIDEO! I tested the AI-powered #PromptLock ransomware, and it failed spectacularly! 🤯

Impact: 0/10. Fun: 11/10.

Watch it here: www.youtube.com/watch?v=-qex...

#Ransomware #AI #Cybersecurity
I Tested The World's First "AI Ransomware"... And It Was A Disaster
YouTube video by Malfind Labs
www.youtube.com
October 8, 2025 at 7:12 AM
First AI-powered ransomware spotted, but it’s not active – yet

Oh, look, a use case for OpenAI's gpt-oss-20b model ESET malware researchers Anton Cherepanov and Peter Strycek have discovered what they describe as the "first known AI-powered ransomware," which they named PromptLock. …
First AI-powered ransomware spotted, but it’s not active – yet
Oh, look, a use case for OpenAI's gpt-oss-20b model ESET malware researchers Anton Cherepanov and Peter Strycek have discovered what they describe as the "first known AI-powered ransomware," which they named PromptLock. …
go.theregister.com
August 26, 2025 at 9:39 PM
Researchers at ESET identified PromptLock, the first AI-powered ransomware, discovered on Aug. 25.
Researchers flag code that uses AI systems to carry out ransomware attacks
cyberscoop.com
August 27, 2025 at 12:32 PM
Experimental PromptLock ransomware uses AI to encrypt, steal data

Threat researchers discovered the first AI-powered ransomware, called PromptLock, that uses Lua scripts to steal and encrypt data on Windows, macOS, and Linux systems. [...]

#hackernews #news
Experimental PromptLock ransomware uses AI to encrypt, steal data
Threat researchers discovered the first AI-powered ransomware, called PromptLock, that uses Lua scripts to steal and encrypt data on Windows, macOS, and Linux systems. [...]
www.bleepingcomputer.com
August 29, 2025 at 12:57 AM
ESET Research uncovers 'PromptLock,' the first AI-powered ransomware using OpenAI's gpt-oss:20b model to generate malicious Lua scripts. A significant evolution in malware design. #CyberSecurity #AI #Ransomware Link: thedailytechfeed.com/promptlock-t...
August 27, 2025 at 4:56 PM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 7, 2025 at 5:01 AM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 6, 2025 at 8:33 PM
AI-Powered Ransomware Has Arrived With ‘PromptLock’

Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
AI-Powered Ransomware Has Arrived With ‘PromptLock’
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
www.darkreading.com
September 6, 2025 at 10:32 PM
The first known ransomware family to rely on AI systems for local operations has been discovered.

www.securityweek.com/promptlock-f...
PromptLock: First AI-Powered Ransomware Emerges
PromptLock malware leverages AI to create Lua scripts for data exfiltration and encryption across Windows and Linux systems.
www.securityweek.com
August 29, 2025 at 7:55 AM
First Recognized AI-powered Ransomware Uncovered By ESET Analysis

The invention of PromptLock reveals how malicious use of AI fashions might supercharge ransomware and different threats 26 Aug 2025 • , 2 min. learn ESET researchers have found what they known as “the primary recognized AI-powered…
First Recognized AI-powered Ransomware Uncovered By ESET Analysis
The invention of PromptLock reveals how malicious use of AI fashions might supercharge ransomware and different threats 26 Aug 2025 • , 2 min. learn ESET researchers have found what they known as “the primary recognized AI-powered ransomware”. The malware, which ESET has named PromptLock, has the power to exfiltrate, encrypt and probably even destroy information, although this final performance seems to not have been carried out within the malware but. Whereas PromptLock was not noticed in precise assaults and is as an alternative considered a proof-of-concept (PoC) or a piece in progress, ESET’s discovery reveals how malicious use of publicly-available AI instruments might supercharge ransomware and different pervasive cyberthreats.
nextbusiness24.com
August 30, 2025 at 5:22 PM
ESET warns of PromptLock, the first AI-driven ransomware
ESET warns of PromptLock, the first AI-driven ransomware
ESET found PromptLock, the first AI-driven ransomware, using OpenAI’s gpt-oss:20b via Ollama to generate and run malicious Lua scripts.
securityaffairs.com
August 27, 2025 at 10:04 AM
Шкідливе програмне забезпечення під назвою PromptLock використовує локально доступну модель мови штучного інтелекту для генерації шкідливих скриптів у режимі реального часу. Під час інфікування штучний інтелект автоматично вирішує, які файли шукати, копіювати або шифрувати.
Нова програма-вимагач використовує штучний інтелект для кібератак | CyberCalm
PromptLock створює скрипти Lua, які працюють на всіх платформах, зокрема Windows, Linux та macOS. Загроза сканує локальні файли, аналізує їхній вміст та на
cybercalm.org
August 28, 2025 at 6:04 AM