Executive Summary
In September 2025, ESET Research identified PromptLock, the first documented case of AI-powered ransomware. While not deployed in active attacks, PromptLock is a sophisticated proof-of-concept that leverages OpenAI’s gpt-oss-20b model via the Ollama API to create malicious Lua scripts in real-time. Written in Golang for both Windows and Linux, PromptLock automates enumeration, exfiltration, and encryption of target system files, with variants found on VirusTotal. Its design demonstrates the feasibility of AI-augmented malware, where dynamic scripting enables rapid adaptation to environments and highly automated attack flows.
PromptLock’s discovery highlights the emergence of AI-driven tactics that could accelerate ransomware development and proliferation. As AI tools become more accessible, the risk of advanced, autonomous threats challenging enterprise security controls grows sharply, signaling a pivotal shift in the threat landscape.
Why This Matters Now
PromptLock marks a turning point: adversaries now leverage public AI models to automate and scale ransomware operations. This lowers the technical barrier for attackers and could spur a surge in highly-adaptive, AI-orchestrated cyber threats, pressuring organizations to rethink response and defenses before such tools are used at scale in real-world breaches.
Attack Path Analysis
The attacker leveraged AI-powered ransomware, likely infiltrating internal cloud workloads via phishing or exposed services, to establish initial access. After landing, the malware likely enumerated the environment to obtain necessary privileges, then used automated Lua scripts to traverse and target additional systems. Command and control was facilitated through dynamically generated scripts, possibly blending activity into normal traffic. Sensitive files were exfiltrated via outbound channels before the AI-powered ransomware encrypted data, disrupting business processes and demanding payment.
Kill Chain Progression
Initial Compromise
Description
The attacker likely gained access via phishing or exploitation of exposed cloud workloads, deploying the PromptLock AI-powered ransomware in Windows and Linux environments.
MITRE ATT&CK® Techniques
Command and Scripting Interpreter
Data Encrypted for Impact
Exfiltration Over Web Service
File and Directory Discovery
Process Injection
Obfuscated Files or Information
Native API
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Storage of Sensitive Data
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Requirements
Control ID: Article 12(2)
NIS2 Directive – Implementation of Security Policies and Procedures
Control ID: Article 21(2)(c)
CISA Zero Trust Maturity Model 2.0 – Continuous Monitoring and Automated Response
Control ID: Data Pillar – Continuous Data Protection
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
AI-powered ransomware threatens encrypted transactions and customer data, exploiting east-west traffic vulnerabilities while evading traditional detection mechanisms through adaptive scripting.
Health Care / Life Sciences
PromptLock's data exfiltration capabilities pose severe HIPAA compliance risks, threatening patient records through zero-trust segmentation gaps and multicloud visibility weaknesses.
Information Technology/IT
Cross-platform Golang malware targets IT infrastructure through Kubernetes vulnerabilities, leveraging cloud firewall bypasses and inline IPS evasion via AI-generated Lua scripts.
Government Administration
AI-enhanced ransomware represents critical national security threat through automated reconnaissance and real-time attack adaptation, challenging traditional cybersecurity defense frameworks.
Sources
- First known AI-powered ransomware uncovered by ESET Researchhttps://www.welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research/Verified
- ESET discovers PromptLock, the first AI-powered ransomwarehttps://www.eset.com/gr-en/about/newsroom/press-releases-1/eset-discovers-promptlock-the-first-ai-powered-ransomware-1/Verified
- ESET Threat Report: AI-driven attacks on the rise; NFC threats increase and evolve in sophisticationhttps://www.eset.com/us/about/newsroom/research/eset-threat-report-h2-2025-1/Verified
- Researchers discover AI-powered ransomwarehttps://cybernews.com/cybercrime/promptlock-ai-powered-ransomware/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix CNSF and Zero Trust controls such as east-west segmentation, policy-based egress filtering, encrypted traffic inspection, and network visibility would have sharply limited PromptLock's ability to propagate, exfiltrate data, or encrypt workloads across cloud environments.
Control: Cloud Firewall (ACF)
Mitigation: Prevents unauthorized inbound connections to workloads.
Control: Threat Detection & Anomaly Response
Mitigation: Detects suspicious privilege or filesystem enumeration behaviors.
Control: Zero Trust Segmentation
Mitigation: Blocks lateral movement between workloads and regions.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks known C2 and malicious outbound traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized data exfiltration via strict outbound controls.
Limits ransomware's ability to encrypt workloads at scale.
Impact at a Glance
Affected Business Functions
- Data Management
- IT Operations
- Compliance
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exfiltration and encryption of sensitive data, leading to operational downtime and compliance violations.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce east-west zero trust segmentation to contain the blast radius of AI-driven ransomware across cloud workloads.
- • Apply granular egress controls with DNS/FQDN filtering to stop exfiltration and C2 activity from compromised hosts.
- • Deploy real-time anomaly detection to rapidly catch outlier privilege use, filesystem activity, and encrypted ransomware traffic.
- • Harden cloud perimeters and only expose necessary services using robust, distributed cloud firewalls.
- • Continuously monitor, baseline, and segment hybrid/multicloud environments for all workloads and sensitive data paths.



