AI-Powered Ransomware Emerges: Chirag Goswami Highlights New ‘PromptLock’ Threat

C

Chirag Goswami

LinkedIn Author

Founder @ Cybernara | Security-First Managed IT & Cloud Partner | Cloud, M365 & GRC | LinkedIn Top Voice

In a recent LinkedIn post, Chirag Goswami discusses the emergence of a new form of ransomware, dubbed ‘PromptLock,’ which leverages artificial intelligence to generate its malicious code. This development marks a significant shift in the cybercrime landscape, as highlighted by Goswami.

Goswami points out the fundamental change this represents in ransomware attacks:

“The shift: Attackers no longer need to code everything manually. AI can generate new malicious variants on demand, making detection and defense far harder.”

The process, as detailed by Goswami, involves attackers using a local AI model, specifically mentioning ‘gpt-oss-20b via Ollama API,’ to create malicious scripts. These scripts are then disseminated to victims via various channels, including emails, downloads, or external media. Once executed on the victim’s device, the AI-generated code proceeds to encrypt files.

The Mechanics of AI-Driven Ransomware

Chirag Goswami breaks down the operational flow of PromptLock, emphasizing its AI-driven nature. According to Goswami, the core innovation lies in the AI’s ability to generate the ransomware’s code.

He elaborates on the steps involved:

  1. Attackers utilize a local AI model to generate malicious scripts.
  2. These scripts are distributed to potential victims.
  3. Upon opening, the script executes on the victim’s system.
  4. Files are encrypted using code that was generated by AI.
  5. The attacker then gains access to the compromised data and presents a ransom demand.

Implications for Cybersecurity

Goswami underscores the profound implications of this AI-powered threat. One of the most concerning aspects, as he notes, is the potential democratization of advanced cybercrime.

“The risk: Low-skilled attackers can now launch advanced ransomware campaigns with AI support.”

This means that individuals with less technical expertise can potentially deploy sophisticated ransomware attacks, significantly broadening the threat surface. The ability of AI to generate novel and varied malicious code also presents a formidable challenge for traditional security measures, which often rely on signature-based detection of known threats.

The Challenge of Evolving Threats

The core challenge presented by PromptLock, according to Goswami, is the dynamic and adaptive nature of AI-generated malware. Unlike manually coded ransomware, which might have predictable patterns, AI can create variants that are harder to detect and analyze.

As Chirag Goswami explains:

“It’s called PromptLock. 🔒💀 At first glance, it looks like just another ransomware strain. But if you look closer, this is AI-powered cybercrime in action. âš¡”

This adaptability means that cybersecurity defenses must evolve rapidly to keep pace. Goswami’s post serves as a crucial alert to organizations about the necessity of preparing for these next-generation threats.

Preparing for AI-Powered Attacks

Chirag Goswami, in his capacity at Cybernara, suggests that organizations need robust strategies to counter these advanced threats. He advocates for proactive measures rather than reactive ones.

He states:

“At Cybernara, we help organizations prepare for next-generation threats with proactive monitoring, compliance, and incident response strategies.”

Goswami encourages businesses to focus on building resilience through comprehensive cybersecurity practices, including continuous monitoring, adherence to compliance standards, and well-defined incident response plans. His call to action is for leaders to connect and discuss building defenses against the rising tide of AI-powered cyberattacks.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on September 3, 2026 | View original post on LinkedIn →