• News/
  • https://www.theregister.com/2025/08/26/first_aipowered_ransomware_spotted_by/

First AI-powered ransomware spotted, but it's not active – yet

The Register
·
Jessica Lyons
·
Published Aug 26, 2025
·
Updated

ESET malware researchers Anton Cherepanov and Peter Strycek have discovered what they describe as the "first known AI-powered ransomware," which they named PromptLock. The good news, according to the duo, who detailed PromptLock in a series of social media posts and screenshots on Tuesday, is that the malware doesn't appear to be fully functional — yet. The Register has learned that the AI-powered malware, which ESET named PromptLock, was uploaded to VirusTotal by a team at the NYU Tandon School of Engineering. After this story was published, the Tandon team alerted us that they had uploaded the proof-of-concept, which they named Ransomware 3.0, during testing, and ESET’s Anton Cherepanov and Peter Strycek later discovered it without knowing its academic origins. “While it is the first to be AI-powered, the ransomware prototype is a proof-of-concept that is non-functional outside of the contained lab environment,” the academics said. "Although multiple indicators suggest the sample is a proof-of-concept (PoC) or work-in-progress rather than fully operational malware deployed in the wild, we believe it is our responsibility to inform the cybersecurity community about such developments," Cherepanov and Strycek wrote. However, despite the lack of in-the-wild PromptLock infections, the discovery does show that AI has made cybercriminals' attack chains that much easier, and should serve as a warning to defenders. The PromptLock malware uses Open AI's gpt-oss-20b model, which is on...

Read full article

Affected Software

2 affected components
ESET PromptLock
NYU Tandon School of Engineering Ransomware 3.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of the first known AI-powered ransomware named PromptLock.

2

What security implications are discussed in relation to AI-powered ransomware?

The article highlights the potential threat posed by AI-powered ransomware and its ability to evolve in sophistication.

3

What products or software are affected by this AI-powered ransomware?

The affected software mentioned in the article includes ESET's PromptLock and NYU Tandon School of Engineering's Ransomware 3.0.

4

Is the AI-powered ransomware currently active?

No, the article states that the AI-powered ransomware PromptLock is not active yet.

5

Who discovered the AI-powered ransomware PromptLock?

The discovery of PromptLock was made by ESET malware researchers Anton Cherepanov and Peter Strycek.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
First AI-powered ransomware spotted, but it's not active – yet - SecAlerts