Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Proteasome inhibitor combination expands treatment of AML

Maternal PFAS levels are linked to children’s brain development

F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Someone created the first AI-powered ransomware using Openai’s GPT-oss:20B model
Identity

Someone created the first AI-powered ransomware using Openai’s GPT-oss:20B model

userBy userAugust 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Cybersecurity company ESET has revealed it has discovered PromptLock, a ransomware variant codenamed PromptLock, powered by artificial intelligence (AI).

The newly identified strain written in Golang generates malicious LUA scripts in real time using Openai’s GPT-OSS:20B model via the Ollama API. The Open-Weight Language model was released by Openai earlier this month.

“Promptlock leverages LUA scripts generated from hardcoded prompts to enumerate local file systems, inspect target files, remove selected data, and perform encryption,” ESET said. “These LUA scripts are cross-platform compatible and work on Windows, Linux, and MacOS.”

Ransomware code embeds steps to create custom notes based on “affected files”, and the infected machine can be a personal computer, company server, or power distribution controller. It is currently unclear who is behind the malware, but ESET told Hacker News that Artifact was uploaded to Virustotal from the US on August 25, 2025.

Cybersecurity

“PromptLock uses AI-generated LUA scripts, meaning the compromise metric (IOC) can vary depending on the execution,” pointed out Slovak Cybersecurity Company. “This variation poses detection challenges. If implemented properly, such an approach can significantly complicate threat identification and make defender tasks more difficult.”

Recognised as a proof of concept (POC), rather than fully working malware deployed in the wild, Promptlock uses the SPECK 128-bit encryption algorithm to lock files.

In addition to encryption, analysis of ransomware artifacts suggests that the functionality to actually perform erasure does not appear to be implemented yet, but can also be used to remove or destroy it.

“PromptLock doesn’t download the entire model. This could be a few gigabytes in size,” ESET revealed. “Instead, an attacker can simply establish a proxy or tunnel from the compromised network to a server running the Ollama API on the GPT-OSS-20B model.”

The emergence of PromptLock is another indication that AI has made it easier for cybercriminals, even those who lack technical expertise to quickly set up new campaigns, develop malware, and create engaging phishing content and malicious sites.

Today, humanity has revealed that it has banned accounts created by two different threat actors who committed massive theft and fear tor of personal data targeting at least 17 different organizations using the Claude AI chatbot, and developed several variations of ransomware with advanced evasion capabilities, encryption and repetition mechanisms.

The development comes as large language models (LLMs) powering various chatbots and AI-focused developer tools, such as Amazon Q Developer, Anthropic Claude Code, AWS Kiro, Butterfly Effect Manus, Google Jules, Lenovo Lena, Microsoft GitHub Copilot, OpenAI ChatGPT Deep Research, OpenHands, Sourcegraph Amp, and Windsurf, have been found susceptible to prompt injection Attacks, can allow for information disclosure, data stripping, and code execution.

Despite incorporating robust security and safety guardrails to avoid unwanted behavior, AI models repeatedly fall prey to new variants of injection and jailbreak, highlighting the complexity and evolving nature of security challenges.

Identity Security Risk Assessment

“As a rapid injection attack, AIS will delete files, steal data and engage in financial transactions,” says humanity. “New forms of rapid injecting attacks are also constantly being developed by malicious actors.”

Additionally, new research reveals a simple yet clever attack called Promisqroute. “Reconfigure operations using prompt-based router open mode operations, trust avoidance induced via queries like SSRF” – Abuse the ChatGPT model routing mechanism to trigger downgrades and create prompts.

Bypass millions of dollars with additional AI safety research with phrases like “using compatibility mode” and “need fast response,” Absversa AI said in a report released last week, with the attack targeting the cost-saving model routing mechanisms used by AI vendors.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHere are 33 US AI startups that raised over $100 million in 2025:
Next Article James Webbspace Telescope reveals strangeness that the first time he has observed interstellar comet 3i/Atlas
user
  • Website

Related Posts

F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More

October 20, 2025

3 reasons copy/paste attacks cause security breaches

October 20, 2025

131 Chrome extensions found to be hijacking WhatsApp Web in massive spam campaign

October 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Proteasome inhibitor combination expands treatment of AML

Maternal PFAS levels are linked to children’s brain development

F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More

3 reasons copy/paste attacks cause security breaches

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.