PromptLock, also referred to as Ransomware 3.0, is an experimental AI-enabled ransomware proof of concept developed as an academic research prototype at New York University’s Tandon School of Engineering. Written in Go, it invokes the locally hosted gpt-oss-20b language model through the Ollama API and uses hard-coded prompts to generate and execute Lua scripts dynamically. These scripts can enumerate and inspect local files, select data for exfiltration, and encrypt targeted data; an unfinished destructive capability was also present. PromptLock uses SPECK 128-bit encryption. Windows and Linux variants have been identified, and its generated Lua logic was designed for cross-platform operation, including macOS. PromptLock was not observed in real-world attacks and is not established as an operational criminal ransomware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
В терминах MITRE ATT&CK полная цепочка AI-агента выглядит так: Resource Development - атакующий использует публичные или собственные AI-сервисы для генерации артефактов атаки (T1588.007 - Artificial Intelligence), разрабатывает вредоносное ПО с AI-компонентом (T1587.001 - Malware)
It generates Lua scripts customized for each victim's specific computer setup, maps IT systems, and identifies environments
It generates Lua scripts customized for each victim's specific computer setup, maps IT systems, and identifies environments, determining which files are most valuable... In addition to stealing and encrypting data | the AI also wrote a personalized ransom note based on user info and bios found on the infected computer
The malware "has the ability to exfiltrate, encrypt and possibly even destroy data" and "PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption."
Ransomware 3.0 / PROMPTLOCK Ransomware with exfiltration and wipe capability... generate Lua scripts that perform file listing, encryption, exfiltration, and (unfinished) wipe logic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Purported AI-powered ransomware that the article states was a university research project rather than malware deployed in real-world attacks.
Malware family described as generating malicious functions on demand instead of embedding them natively in the binary.
AI-enabled ransomware with an embedded local LLM that operates without external API calls, dynamically generating Lua scripts to adapt encryption and exfiltration behavior to the victim system.
Experimental cross-platform ransomware implemented with Lua scripts as part of the emerging AI-assisted malware trend.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.