Get the latest tech news

The first AI-powered ransomware has been discovered — "PromptLock" uses local AI to foil heuristic detection and evade API tracking


Hackers finally discover a practical use for local AI models

ESET said that this malware uses an open-weight large language model developed by OpenAI to generate scripts that can perform a variety of functions on Windows, macOS, and Linux systems while confounding defensive tools by exhibiting slightly different behavior each time. "PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption," ESET said in a Mastodon post about the malware. The fact that the model runs locally also makes it so OpenAI can't snitch on the ransomware operators—if they had to call an API on its servers every time they generate one of these scripts, the jig would be up.

Get the Android app

Or read this on r/technology

Read more on:

Photo of API

API

Photo of Local AI

Local AI

Photo of powered ransomware

powered ransomware

Related news:

News photo

Show HN: Sideko – Hybrid deterministic/LLM generator for API SDKs and docs

News photo

Everything I know about good API design

News photo

Apple prepping allowing API access to any external LLM model for enterprise on devices beyond ChatGPT