{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/eset-promptlock-ai-ransomware-2025/",
 "asOf": "2026-09-26",
 "id": "eset-promptlock-ai-ransomware-2025",
 "date": "2025-08-26",
 "datePrecision": "day",
 "title": "ESET finds PromptLock, ransomware that writes its scripts with a local LLM, later tied to a research prototype",
 "lane": "attack",
 "kind": "malware",
 "summary": "ESET Research reported PromptLock, ransomware samples uploaded to VirusTotal that use a locally run open-weight model to generate scripts for file discovery, exfiltration and encryption at runtime, and called it the first known AI-powered ransomware. In a September 3, 2025 update, ESET said the authors of an academic study had contacted it and that their research prototype closely resembles the samples, supporting ESET's view that PromptLock was a proof of concept rather than malware used in attacks.",
 "whyItMatters": "What ESET called the first known AI-powered ransomware closely resembled an academic prototype, a caution about how early AI-malware claims are read.",
 "actors": [
  "eset"
 ],
 "topics": [
  "ai-malware"
 ],
 "atlas": [],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research/",
   "publisher": "ESET",
   "title": "First known AI-powered ransomware uncovered by ESET Research",
   "date": "2025-08-26",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "PromptLock runs OpenAI’s gpt-oss-20b model locally through the Ollama API to generate Lua scripts from hard-coded prompts.",
   "locator": "Article body"
  },
  {
   "fact": "Windows and Linux variants were found on VirusTotal; ESET did not see PromptLock in actual attacks.",
   "locator": "Article body"
  },
  {
   "fact": "Update, September 3, 2025: an academic study, Ransomware 3.0, describes a prototype that closely resembles the samples.",
   "locator": "Update note"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "runtime-llm-malware"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}