You’ve likely heard about ransomware for years — that type of malware that “kidnaps” a company’s or individual’s files, encrypts them, and demands payment for their release. Nothing new there. What’s radically changing now is this: you no longer need a team of expert programmers writing malicious code. With Promptlock, ransomware is now generated and adapted autonomously using artificial intelligence.
At TecnetOne, we break down how this new threat works, why it’s so dangerous, and what you should do to protect your business.
Unlike traditional ransomware built with prewritten code, Promptlock functions like a generative AI. Instead of executing a static script, it dynamically creates malicious code depending on the system it infiltrates.
Whether your organization runs Windows, Linux, or macOS, this malware can automatically craft instructions to adapt to your environment. Regardless of the infrastructure, Promptlock finds a way to exploit weaknesses and achieve its goal.
Written in Golang, a versatile programming language, Promptlock uses 128-bit encryption to lock files. But what’s even more alarming is its ability to copy and exfiltrate data before encrypting it — so not only do you risk losing access to your data, but also having it leaked or sold on the dark web.
The infection flow is unlike anything we've seen:
Because the malware is dynamically generated, it’s significantly harder to detect using traditional antivirus solutions.
Also of interest: The Evolution of Artificial Intelligence Driven Malware
Most cybersecurity tools rely on signatures — known patterns or code snippets to flag ransomware. Promptlock changes that game entirely. It rewrites itself with every infection, producing virtually endless variations.
ESET researchers discovered the first instances of this malware and submitted them to platforms like VirusTotal. While still categorized as a proof of concept, the threat is very real — any malicious actor with access to generative AI can now launch their own customized variant.
Generative AI has brought enormous benefits in productivity, creativity, and automation. But in the wrong hands, it becomes a devastating weapon.
Promptlock exemplifies this: an AI that creates, adapts, and executes malicious code without human programming. This lowers the barrier to entry for cybercriminals and enables even low-skilled attackers to launch complex campaigns.
Whether you're a small business or a large enterprise, the risks are serious:
Promptlock signals a paradigm shift in cybercrime. Attacks are no longer launched with static malware — instead, they're powered by AI-driven tools that adapt in real time.
This means that defenses must also evolve. Antivirus software alone is not enough. Companies now need integrated strategies, including:
Read more: Xanthorox AI: A New Malicious AI Tool Emerges on the Darknet
ESET researchers and cybersecurity experts suggest the following:
At TecnetOne, we know no system is 100% immune. That’s why having a strong incident response service is essential. Our approach includes:
Promptlock is proof that cybersecurity has entered a new era — one where AI doesn’t just protect, it attacks. Its speed and adaptability make it a real threat for organizations of all sizes.
What once sounded like science fiction is now reality: malware that writes and rewrites itself to stay undetected.
The question is no longer if your company will be attacked — it’s when. And when it happens, how prepared will you be?
At TecnetOne, we help you prepare, respond, and recover — without paying the price of ransom. Let’s talk.