PromptLock

First seen
2023-10-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-12 11:33:45
Profile updated
2026-07-07 13:17:08

Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical government-and-public-sector

Context

According to ESET Research, PromptLock is first known AI-powered ransomware. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption. These Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS. For its file encryption mechanism, the PromptLock ransomware utilizes the SPECK 128-bit encryption algorithm.

Reports & references

  • cloud.google.com — Threat Actor Usage Of Ai Tools (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Prompt Lock (report)
  • x.com — 1960365407463751889 (report)

External references