PromptLock: The First AI-Powered Ransomware Uncovered

Łukasz Grochal

ESET researchers have revealed PromptLock, a proof-of-concept ransomware that dynamically generates malicious code using a local AI model. Written in Go, it employs OpenAI’s gpt-oss:20b via the Ollama API to produce Lua scripts at runtime. These scripts enumerate files, exfiltrate data, and encrypt it using SPECK 128-bit, with potential (but not yet active) destructive capabilities.

Designed for cross-platform deployment across Windows, Linux, and macOS, the non-deterministic script generation complicates detection by traditional tools. The presence of a Bitcoin address linked to Satoshi Nakamoto further points to ransom demands.

While not seen in real-world attacks, PromptLock signals the growing sophistication of ransomware threats.

References
3 sources
01
eset.comEset
02
cybersecuritynews.comCyber Security News
03
itnews.com.auitNews
Palantir Manifesto Graphic: AI Defense and Culture Clash

Palantir Manifesto Hits at Regressive Cultures and AI Shift

Europe Digital Sovereignty and Big Tech Dependence

Europe’s Push for Digital Sovereignty Is Changing the Game

Palantier Dilemma Human Rights vs Sercurity

Europe's Palantir Boom Amid Sovereignty and Rights Fears

Denuvo Has Been Cracked

How Denuvo Was Bypassed, and Why It Took So Long

Palantir AIPCon stage with defense AI demonstrations

Palantir, Anthropic And The Battle For AI In War

Project Maven Dashboards Visualizing Targets and Risks

Claude, Palantir and Who Controls AI in Modern War

Palantir The Company You Do Not Know, Yet Shapes Your World

Inside Palantir: The Tolkien‑Inspired Data Empire

Kremlin Bans WhatsApp: Runet Lockdown Phone Image

Russia Blocks WhatsApp to Enforce Runet Sovereignty

Secure Proton Mail Encryption Shield Icon 2026

Proton Mail: Swiss Privacy Leader from CERN Roots

Poland Under Fire From Record Cyberattacks

Why Poland Became A Prime Target For Global Cyberattacks