World’s First AI-Powered Ransomware ‘PromptLock’ Emerges Using GPT-OSS-20B
ID: b4925f95-e45b-5f2b-b1a3-79173f9dd41f
STIX ID: report--b4925f95-e45b-5f2b-b1a3-79173f9dd41f
Feed Name: Cyber Press
PromptLock is a proof-of-concept ransomware that integrates a locally hosted LLM (gpt-oss:20b via the Ollama API) to dynamically generate cross-platform Lua payloads at runtime. Implemented in Go and distributed as Windows and Linux samples on VirusTotal, it sends hard-coded prompt templates to a local Ollama endpoint (e.g., `172.42.0.253:8443`) to produce Lua scripts that perform system enumeration, filesystem inspection (using LuaFileSystem), selective exfiltration, and encryption (AES-style containers and SPECK 128-bit). ESET researchers note it remains developmental (some functions unimplemented) and no active deployments have been observed, but the report includes IoCs (malware family Filecoder.PromptLock.A and multiple SHA1s) and recommends monitoring anomalous local API traffic and behavior-based detection for future AI-driven malware threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
