Rogue Agents Watch › Records › promptlock-ai-ransomware-poc

PromptLock — first known AI-powered ransomware (academic proof-of-concept)

Disclosed · added to the index · last updated

Grades

Verification status
Test / evaluation — Occurred in a controlled lab test, red-team exercise, or evaluation — not a real-world attack.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
Medium — Limited or contained harm, or high-signal capability demonstration.

Summary

ESET Research disclosed "PromptLock" on 2025-08-26 as the first known AI-powered ransomware after discovering samples uploaded to VirusTotal. The Go-based code used a locally hosted large language model (OpenAI's gpt-oss:20b via the Ollama API) to generate malicious Lua scripts at runtime for file enumeration, exfiltration and encryption. ESET assessed it as a proof-of- concept; researchers at NYU Tandon subsequently confirmed it originated from their academic project "Ransomware 3.0" and was never deployed in a real attack.

Impact as stated

No real-world impact: an academic proof-of-concept demonstrating a closed-loop, LLM-orchestrated ransomware workflow (reconnaissance, exfiltration and encryption). ESET maintains it is the first known case of AI-powered ransomware while agreeing it was a proof-of-concept, not operational malware.

Facts as stated by sources

Actor
NYU Tandon School of Engineering research team (Researcher)
Category
Lab escape / evaluation
Models named
gpt-oss:20b
Model families
GPT (OpenAI)
Agentic autonomy level
Fully-autonomous
Guardrail bypass
Open-weight model
Attack lifecycle phases
Reconnaissance, Exfiltration, Impact
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0102, AML.T0016.002

Map

No cited source states a location; this record is listed beside the map, never plotted.

Sources (2)

  1. First known AI-powered ransomware uncovered by ESET Research
    ESET WeLiveSecurity · Vendor report · · archived copy
  2. NYU team behind AI-powered malware dubbed 'PromptLock'
    CyberScoop · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptlock-ai-ransomware-poc". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptlock-ai-ransomware-poc.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction