PromptLock is an experimental, AI-assisted ransomware proof of concept identified by ESET in August 2025. It was subsequently linked to the Ransomware 3.0 research prototype developed at New York University’s Tandon School of Engineering. It has not been observed in real-world attacks and has no established association with a criminal threat actor or targeted industry.
Written in Go, PromptLock uses hard-coded prompts to query OpenAI’s gpt-oss-20b model through a local Ollama API. It generates and executes Lua scripts at runtime rather than implementing all malicious functions directly in its binary. These scripts enumerate the local filesystem, inspect file contents, select data for exfiltration, and encrypt files. Its model-directed workflow demonstrates how runtime code generation can adapt ransomware actions to the host environment. Destructive functionality was contemplated but was not implemented or active in the analyzed samples. Windows and Linux variants were identified on VirusTotal.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
В терминах MITRE ATT&CK полная цепочка AI-агента выглядит так: Resource Development - атакующий использует публичные или собственные AI-сервисы для генерации артефактов атаки (T1588.007 - Artificial Intelligence), разрабатывает вредоносное ПО с AI-компонентом (T1587.001 - Malware)
It generates Lua scripts customized for each victim's specific computer setup, maps IT systems, and identifies environments
It generates Lua scripts customized for each victim's specific computer setup, maps IT systems, and identifies environments, determining which files are most valuable... In addition to stealing and encrypting data | the AI also wrote a personalized ransom note based on user info and bios found on the infected computer
The malware "has the ability to exfiltrate, encrypt and possibly even destroy data" and "PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption."
Ransomware 3.0 / PROMPTLOCK Ransomware with exfiltration and wipe capability... generate Lua scripts that perform file listing, encryption, exfiltration, and (unfinished) wipe logic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named AI-assisted malware example described as using language models to modify payloads while operating.
Malware described as using language models to alter its payload during execution.
Purported AI-powered ransomware that the article states was a university research project rather than malware deployed in real-world attacks.
Malware family described as generating malicious functions on demand instead of embedding them natively in the binary.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.