PromptLock is an experimental AI-enabled ransomware proof of concept, also referred to as Ransomware 3.0, that embeds a locally accessible large language model into its execution flow. It is written in Go and uses hard-coded prompts to invoke the gpt-oss-20b model through a local Ollama API, dynamically generating Lua scripts at runtime rather than relying solely on prebuilt ransomware logic. The generated scripts perform filesystem enumeration, inspect files, select data for theft, and encrypt targeted content, demonstrating how generative AI can be used to adapt malicious behavior to the victim environment during execution.
PromptLock has been described as the first known ransomware to integrate an LLM directly into active operations, but available reporting indicates it was not observed in real-world criminal deployment and was instead a research prototype closely matching an academic proof of concept developed at New York University’s Tandon School of Engineering. ESET assessed it as a proof of concept or work in progress rather than an operational campaign.
The malware is cross-platform in design. Reporting supports Windows and Linux variants, and some descriptions state the generated Lua logic was intended to be portable across Windows, Linux, and macOS. Its core demonstrated capabilities include data exfiltration and file encryption, with references to unfinished destructive or wipe-oriented logic that did not appear to be implemented in analyzed samples. PromptLock is significant primarily as an early demonstration of runtime LLM orchestration in malware, showing how publicly available local AI tooling could automate reconnaissance, target selection, and ransomware actions while potentially increasing adaptability and complicating static detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
В терминах MITRE ATT&CK полная цепочка AI-агента выглядит так: Resource Development - атакующий использует публичные или собственные AI-сервисы для генерации артефактов атаки (T1588.007 - Artificial Intelligence), разрабатывает вредоносное ПО с AI-компонентом (T1587.001 - Malware)
It generates Lua scripts customized for each victim's specific computer setup, maps IT systems, and identifies environments
It generates Lua scripts customized for each victim's specific computer setup, maps IT systems, and identifies environments, determining which files are most valuable... In addition to stealing and encrypting data | the AI also wrote a personalized ransom note based on user info and bios found on the infected computer
The malware "has the ability to exfiltrate, encrypt and possibly even destroy data" and "PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption."
Ransomware 3.0 / PROMPTLOCK Ransomware with exfiltration and wipe capability... generate Lua scripts that perform file listing, encryption, exfiltration, and (unfinished) wipe logic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AI-enabled ransomware with an embedded local LLM that operates without external API calls, dynamically generating Lua scripts to adapt encryption and exfiltration behavior to the victim system.
Experimental cross-platform ransomware implemented with Lua scripts as part of the emerging AI-assisted malware trend.
Referenced only as earlier AI-powered ransomware identified by ESET.
Proof-of-concept LLM-assisted malware mentioned for comparison with JADEPUFFER; described as relying on a human-built workflow with the LLM used for specific subroutines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.