Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors promptlock

Description

First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

PromptLock is a medium-sophistication criminal threat actor known for deploying AI-powered ransomware. The actor utilizes the gpt-oss:20b model via OpenAI's Ollama API to generate highly customized malicious Lua scripts on-the-fly. This capability enables PromptLock to target specific sectors and regions with tailored attack vectors, focusing primarily on financial gain through ransom demands.

Goals & Targeting

PromptLock's strategic objectives are centered around organizational-gain and financial-motivation. The actor targets sectors with high data value, such as healthcare or financial institutions, due to the higher ransom potential. The targeting profile appears indiscriminate geographically but focuses on regions where victims may have weaker cybersecurity defenses.

Enhanced Description

PromptLock represents a崭新的一类威胁,以人工智能赋能的勒索软件为特色。该恶意软件的独特之处在于其采用开源AI模型生成动态脚本的能力。通过将GPT-20B大语言模型集成到Ollama API中,PromptLock能够实时生成高度定制化的恶意Lua脚本,从而实现针对特定目标的精准攻击。这种技术使得威胁行为者能够绕过传统的静态签名检测,并根据受害者的特点调整其攻击策略。当前情报表明,PromptLock主要针对那些数据价值高且支付能力强的行业展开行动,但具体的地理和行业偏好尚未完全确定。

Key Capabilities

  • AI-driven generation of malicious Lua scripts using GPT-20B via Ollama API
  • Modular command-and-control (C2) infrastructure for encrypted communication
  • Asymmetric encryption for data exfiltration and ransomware deployment

MITRE ATT&CK Tactics

Disruption
Financial Gain

ATT&CK Techniques

T1059.003
T1566.001
T1208

Software / Tooling

Ollama API (for AI scripting)
Lua scripting engine
Custom encryption tools for data exfiltration and ransomware

Campaigns & Victims

PromptLock campaigns are characterized by their use of novel AI-driven attack vectors. The actor appears to target victims with weak defensive postures, exploiting the combination of static file analysis avoidance (via dynamic script generation) and tailored payloads. Recent campaign activity suggests a focus on healthcare and financial sector targets in North America and Europe.

IOC Patterns

  • Spear-phishing emails containing malicious Lua scripts generated via GPT-20B
  • C2 communication channels leveraging the Ollama API
  • Encrypted files with asymmetric encryption techniques

Recommended Actions

  • Implement AI detection capabilities for script-based threats
  • Monitor network traffic for known Ollama API endpoints
  • Enhance endpoint protection to detect and block malicious Lua scripts
  • Conduct regular sector-specific ransomware simulations

Suggested Tags

APT
ransomware
financial-motivation
healthcare-target
artificial-intelligence

Confidence Assessment

High confidence in the actor's AI-driven capabilities and primary motivations. The targeting profile is less certain but inferred from incident reports. Further intelligence gathering on campaign patterns and victimology could improve situational awareness.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

6

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
financial-motivation
healthcare-target
artificial-intelligence

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.