PromptLock
- First seen
- 2023-10-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-12 11:33:45
- Profile updated
- 2026-07-07 13:17:08
Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical government-and-public-sector
Context
According to ESET Research, PromptLock is first known AI-powered ransomware. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption. These Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS. For its file encryption mechanism, the PromptLock ransomware utilizes the SPECK 128-bit encryption algorithm.
Reports & references
- cloud.google.com — Threat Actor Usage Of Ai Tools (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Prompt Lock (report)
- x.com — 1960365407463751889 (report)