Validated Containment Architectures are here. →Explore

Executive Summary

In September 2025, ESET Research identified PromptLock, the first documented case of AI-powered ransomware. While not deployed in active attacks, PromptLock is a sophisticated proof-of-concept that leverages OpenAI’s gpt-oss-20b model via the Ollama API to create malicious Lua scripts in real-time. Written in Golang for both Windows and Linux, PromptLock automates enumeration, exfiltration, and encryption of target system files, with variants found on VirusTotal. Its design demonstrates the feasibility of AI-augmented malware, where dynamic scripting enables rapid adaptation to environments and highly automated attack flows.

PromptLock’s discovery highlights the emergence of AI-driven tactics that could accelerate ransomware development and proliferation. As AI tools become more accessible, the risk of advanced, autonomous threats challenging enterprise security controls grows sharply, signaling a pivotal shift in the threat landscape.

Why This Matters Now

PromptLock marks a turning point: adversaries now leverage public AI models to automate and scale ransomware operations. This lowers the technical barrier for attackers and could spur a surge in highly-adaptive, AI-orchestrated cyber threats, pressuring organizations to rethink response and defenses before such tools are used at scale in real-world breaches.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

PromptLock is the first known ransomware to use AI language models for automating malware scripting and attack execution, enabling dynamic adaptation to its environment.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix CNSF and Zero Trust controls such as east-west segmentation, policy-based egress filtering, encrypted traffic inspection, and network visibility would have sharply limited PromptLock's ability to propagate, exfiltrate data, or encrypt workloads across cloud environments.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Prevents unauthorized inbound connections to workloads.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Detects suspicious privilege or filesystem enumeration behaviors.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Blocks lateral movement between workloads and regions.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detects and blocks known C2 and malicious outbound traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized data exfiltration via strict outbound controls.

Impact (Mitigations)

Limits ransomware's ability to encrypt workloads at scale.

Impact at a Glance

Affected Business Functions

  • Data Management
  • IT Operations
  • Compliance
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exfiltration and encryption of sensitive data, leading to operational downtime and compliance violations.

Recommended Actions

  • Enforce east-west zero trust segmentation to contain the blast radius of AI-driven ransomware across cloud workloads.
  • Apply granular egress controls with DNS/FQDN filtering to stop exfiltration and C2 activity from compromised hosts.
  • Deploy real-time anomaly detection to rapidly catch outlier privilege use, filesystem activity, and encrypted ransomware traffic.
  • Harden cloud perimeters and only expose necessary services using robust, distributed cloud firewalls.
  • Continuously monitor, baseline, and segment hybrid/multicloud environments for all workloads and sensitive data paths.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image