Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Malicious Perplexity Comet Browser Obtain Adverts Push Malware By way of Google – Hackread – Cybersecurity Information, Information Breaches, Tech, AI, Crypto and Extra

    October 18, 2025

    How Enterprises Ought to Harden Blockchain Apps in Cloud

    October 18, 2025

    Switchboard-Have an effect on: Emotion Notion Labels from Conversational Speech

    October 18, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»First AI-Powered Ransomware PromptLock Targets Home windows, Linux and macOS
    AI Ethics & Regulation

    First AI-Powered Ransomware PromptLock Targets Home windows, Linux and macOS

    Declan MurphyBy Declan MurphyAugust 28, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    First AI-Powered Ransomware PromptLock Targets Home windows, Linux and macOS
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    ESET has recognized PromptLock, the primary AI-powered ransomware, utilizing OpenAI fashions to generate scripts that concentrate on Home windows, Linux and macOS.

    It was solely a matter of time earlier than synthetic intelligence grew to become a constructing block for cybercriminals. This week, researchers at ESET revealed what they’re calling the primary identified AI-powered ransomware, a prototype dubbed PromptLock, which makes use of an open-weight AI mannequin from OpenAI to generate malicious code on the fly.

    Slightly than carrying a static payload, PromptLock calls on the gpt-oss:20b mannequin by means of the Ollama API, enabling it to write down and execute Lua scripts immediately on a compromised system. These scripts can scan directories, examine recordsdata, exfiltrate chosen information, and encrypt the outcomes, all with out the necessity for prepackaged binaries. That flexibility provides attackers a degree of adaptability not generally seen in conventional ransomware.

    The malware is written in Golang, making it cross-platform, and ESET has already noticed each Home windows and Linux samples uploaded to VirusTotal. As a result of Lua is light-weight and moveable, it permits PromptLock to achieve additional than its ordinary victims and run on techniques usually uncared for by ransomware operators, together with macOS and shopper Linux units.

    Apparently, researchers famous that whereas PromptLock can exfiltrate and encrypt recordsdata, however its skill to destroy information has not but been applied. This, together with a number of tough edges within the code, means that it’s a proof-of-concept or work-in-progress somewhat than a reside marketing campaign concentrating on organisations.

    This screenshot shared by ESET reveals an inventory of features contained in the PromptLock ransomware code. Every entry is actually a perform title that reveals what the malware can do.

    ESET’s findings add to worries that AI-driven malware may make cyberattacks quicker and larger-scale. Simply as machine studying has already been used to create extra convincing phishing lures and deepfake content material, fashions may also be tailored to deal with duties akin to reconnaissance, persistence, or information theft. PromptLock reveals that ransomware authors are already experimenting with this method.

    Commenting on the invention, Nathan Webb, principal advisor at Acumen Cyber, defined why this improvement shouldn’t be dismissed as a easy lab experiment: “That is presumably the primary occasion of an AI-powered piece of ransomware noticed within the wild. Slightly than include a payload, the malware makes use of ChatGPT to write down Lua scripts on the fly, which provides it details about the native system and permits it to view recordsdata, exfiltrate information, and finally encrypt the system.”

    “The usage of Lua right here means that attackers try to make the ransomware platform-agnostic, in order that they’ll goal a wider vary of techniques and environments, particularly these not historically focused as a result of their low market share, like Apple units, and shopper Linux units,” Nathan identified.

    Webb additionally identified that defending towards such threats would require new pondering round script interpreters and OS-level instruments. Safety distributors might want to enhance detection mechanisms that may separate reputable scripts from malicious ones, utilizing their very own machine studying fashions to deobfuscate and analyse behaviour in actual time.



    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Malicious Perplexity Comet Browser Obtain Adverts Push Malware By way of Google – Hackread – Cybersecurity Information, Information Breaches, Tech, AI, Crypto and Extra

    October 18, 2025

    North Korean Hackers Mix BeaverTail and OtterCookie into Superior JS Malware

    October 17, 2025

    Attackers Exploit Zendesk Authentication Challenge to Flood Targets’ Inboxes with Company Notifications

    October 17, 2025
    Top Posts

    Malicious Perplexity Comet Browser Obtain Adverts Push Malware By way of Google – Hackread – Cybersecurity Information, Information Breaches, Tech, AI, Crypto and Extra

    October 18, 2025

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025
    Don't Miss

    Malicious Perplexity Comet Browser Obtain Adverts Push Malware By way of Google – Hackread – Cybersecurity Information, Information Breaches, Tech, AI, Crypto and Extra

    By Declan MurphyOctober 18, 2025

    A brand new malvertising marketing campaign is benefiting from the recognition of Perplexity’s just lately…

    How Enterprises Ought to Harden Blockchain Apps in Cloud

    October 18, 2025

    Switchboard-Have an effect on: Emotion Notion Labels from Conversational Speech

    October 18, 2025

    Flexiv Forecasts the Way forward for Robotics at IROS 2025

    October 18, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.