Rogue Agents Watch › Records › promptlock-ai-ransomware-poc
PromptLock — first known AI-powered ransomware (academic proof-of-concept)
Disclosed · added to the index · last updated
Grades
- Verification status
- Test / evaluation — Occurred in a controlled lab test, red-team exercise, or evaluation — not a real-world attack.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
ESET Research disclosed "PromptLock" on 2025-08-26 as the first known AI-powered ransomware after discovering samples uploaded to VirusTotal. The Go-based code used a locally hosted large language model (OpenAI's gpt-oss:20b via the Ollama API) to generate malicious Lua scripts at runtime for file enumeration, exfiltration and encryption. ESET assessed it as a proof-of- concept; researchers at NYU Tandon subsequently confirmed it originated from their academic project "Ransomware 3.0" and was never deployed in a real attack.
Impact as stated
No real-world impact: an academic proof-of-concept demonstrating a closed-loop, LLM-orchestrated ransomware workflow (reconnaissance, exfiltration and encryption). ESET maintains it is the first known case of AI-powered ransomware while agreeing it was a proof-of-concept, not operational malware.
Facts as stated by sources
- Actor
- NYU Tandon School of Engineering research team (Researcher)
- Category
- Lab escape / evaluation
- Models named
- gpt-oss:20b
- Model families
- GPT (OpenAI)
- Agentic autonomy level
- Fully-autonomous
- Guardrail bypass
- Open-weight model
- Attack lifecycle phases
- Reconnaissance, Exfiltration, Impact
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0102, AML.T0016.002
Map
No cited source states a location; this record is listed beside the map, never plotted.
Sources (2)
- First known AI-powered ransomware uncovered by ESET Research
ESET WeLiveSecurity · Vendor report · · archived copy - NYU team behind AI-powered malware dubbed 'PromptLock'
CyberScoop · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptlock-ai-ransomware-poc". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptlock-ai-ransomware-poc.json — CC BY-SA 4.0.