ESET Research discovers PromptLock, a new type of ransomware using GenAI to execute attacks. PromptLock creates Lua scripts that are compatible across platforms, including Windows, Linux, and macOS. It scans local files, analyzes their content, and – based on predefined text prompts – determines whether to exfiltrate or encrypt the data. A destructive function is already embedded in the code, though it remains inactive for now.PromptLock uses a freely available language model accessed via an API, meaning the generated malicious scripts are served directly to the infected device. Notably, the prompt includes a Bitcoin address reportedly linked to Bitcoin creator Satoshi Nakamoto. Is AI opening doors to new and complex threats ?

