• News/
  • https://www.theregister.com/2025/09/03/ransomware_ai_abuse/

Here's how ransomware crims are abusing AI tools

The Register
·
Jessica Lyons
·
Published Sep 3, 2025
·
Updated

It's no secret that AI tools make it easier for cybercriminals to steal sensitive data and then extort victim organizations. But two recent developments illustrate exactly how much LLMs lower the bar for ransomware and other financially motivated cybercrime - and provide a glimpse to defenders about what's on the horizon. ESET malware researchers Anton Cherepanov and Peter Strýček recently sounded the alarm on what they called the "first known AI-powered ransomware," which they named PromptLock. While it later came to light that the proof-of-concept malware had been uploaded to VirusTotal by academics - not criminals - "in theory, it could be used against organizations," Cherepanov told The Register. Plus, "it demonstrates that these systems are sophisticated enough to deceive security experts into thinking they're real malware from attack groups," New York University engineering student and doctoral candidate Md Raz said. And its emergence should put defenders on notice that ransomware development via AI is no longer a future, theoretical threat. Around the same time as ESET's malware hunters spotted PromptLock, Anthropic warned that a cybercrime crew used its Claude Code AI tool in a data extortion operation that hit 17 organizations, with the crims demanding ransoms ranging from $75,000 to $500,000 for the stolen data. The model maker said the extortionists used Claude Code in all phases of the operation, from conducting automated reconnaissance and target discovery to exp...

Read full article

Affected Software

1 affected component
ESET malware
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how ransomware criminals are utilizing AI tools to enhance their cyberattacks.

2

What security implications are discussed in the article?

The article highlights the increased risk and ease with which cybercriminals can conduct ransomware attacks by leveraging AI technologies.

3

What recent developments in AI are mentioned in relation to ransomware?

The article outlines two recent developments that demonstrate how LLMs make ransomware more accessible to criminals.

4

What types of organizations are primarily targeted by these AI-enhanced ransomware attacks?

The article emphasizes that various victim organizations, particularly those with sensitive data, are the primary targets.

5

What software is specifically mentioned as being related to this AI-driven ransomware threat?

ESET malware is mentioned as a product linked to the emergence of AI tools in ransomware attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203