• Skip to main content
  • Skip to secondary menu
  • Skip to footer

Cybersecurity Market

Cybersecurity Technologies & Markets

  • Cybersecurity Events 2025-2026
  • Cybersecurity Jobs
  • Sponsored Post
    • Make a Contribution
  • Market Reports
  • About
    • GDPR
  • Contact

AI-Powered Ransomware Raises the Stakes: ESET Uncovers PromptLock

August 27, 2025 By admin Leave a Comment

ESET’s discovery of PromptLock is not just another entry in the long catalogue of ransomware variants, but a glimpse into how generative AI is reshaping the cyber threat landscape. Unlike traditional ransomware, which relies on static code written and updated by human developers, PromptLock deploys a locally accessible AI model to generate its attack logic dynamically. This means that, during infection, the malware is no longer limited to a predefined playbook. Instead, it can autonomously decide which files to locate, copy, or encrypt, making each incident unique and harder to predict. For defenders, the prospect of combating malware that adapts in real time raises the difficulty level significantly.

The mechanics of PromptLock show just how disruptive this evolution could be. Written in Golang and using the SPECK 128-bit encryption algorithm, it generates Lua scripts compatible with Windows, Linux, and macOS. Once inside a system, it scans files, analyzes their content, and—based on prompt instructions—determines whether to steal or lock the data. The inclusion of a destructive function, dormant for now, signals a chilling potential for future weaponization. By offloading decision-making to an AI model, cybercriminals can skip large portions of manual coding, accelerating attack development while also making their creations less predictable and more resilient against static signature-based defenses.

ESET researchers Anton Cherepanov and Peter Strýček stress the broader implications of this development. PromptLock is currently a proof of concept, but its existence shows how attackers no longer need teams of seasoned programmers. A well-configured AI model, accessible through a free API, is enough to create malware that is self-adapting and multi-platform. The ability to serve malicious scripts directly to an infected device through such a model breaks with the more linear, human-driven approaches of the past. One of the most striking details is the embedded Bitcoin address linked to Satoshi Nakamoto, suggesting either an ironic flourish or an attempt to misdirect attribution.

The cybersecurity community has been anticipating the role AI would play in threat development, and PromptLock may be the first clear sign that we are entering this next phase. The balance of power is shifting toward attackers who can leverage AI as a force multiplier. For defenders, the challenge now is to evolve detection and response mechanisms that can recognize not just known malware families, but also dynamically generated attack logic that mutates in real time. ESET’s decision to release the technical details under the classification Filecoder.PromptLock.A is a call to prepare. The proof of concept may still be in early stages, but the threat it represents is profound—malware that thinks, adapts, and writes itself.

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • The Sleepless Identity: Why AI Now Poses a Data Risk Enterprises Can’t Ignore
  • SentinelOne Expands AI Security Capabilities with New AWS Integrations
  • Resecurity at Milipol Paris 2025
  • CrowdStrike Joins HPE’s Unleash AI Program — A Signal of Where Enterprise AI Security Is Headed
  • Terra Security Unveils Continuous Exploitability Validation for CTEM
  • Lazarus Returns: Upbit Hit by $30M Crypto Heist Using Old playbook
  • AUTOCRYPT Expands Cyber Vision Into MENA: 2026 Marks a Turning Point
  • The Digital Confidence Paradox in Latin America’s Payments Revolution
  • LevelBlue Completes Acquisition of Cybereason, Signaling a New Cybersecurity Power Bloc
  • Palo Alto Networks Acquires Chronosphere for $3.35B: A Signal of Where Cybersecurity Is Headed Next

Media Partners

  • Technology Conferences
  • Technologies
  • Event Sharing Network
  • GameTech Market
  • OSINT
  • Event Calendar
  • Calendarial
  • Media Presser
  • 3V

Media Partners

  • App Coding
  • API Coding
  • Blockchaining
  • S3H
  • Press Club
  • VPNW
  • Opinion
  • Media Press Release
  • Defense Market

Copyright © 2022 CybersecurityMarket.com

Technologies, Market Analysis & Market Research