AI-Powered Ransomware Emerges: Chirag Goswami Highlights PromptLock Threat

C

Chirag Goswami

LinkedIn Author

Founder @ Cybernara | Security-First Managed IT & Cloud Partner | Cloud, M365 & GRC | LinkedIn Top Voice

In a recent LinkedIn post, Chirag Goswami discusses the alarming emergence of ransomware that leverages artificial intelligence to generate its malicious code, a development he identifies as a significant leap in cybercrime capabilities. Goswami introduces PromptLock, a new strain that, while appearing conventional at first glance, represents a sophisticated application of AI in cyberattacks.

“This is the first ransomware that uses an AI model to generate its malicious code. It’s called PromptLock.”

The Mechanics of AI-Driven Ransomware

Chirag Goswami breaks down the operational process of PromptLock, detailing how attackers utilize a local AI model, specifically mentioning gpt-oss-20b via the Ollama API, to craft malicious scripts. These AI-generated scripts are then disseminated to victims through various vectors, including email, direct downloads, or external media. Once a victim opens the compromised script, it executes on their device, initiating the encryption process using AI-generated code.

As Goswami explains, the core innovation lies in the AI’s ability to create new malicious variants on demand. This drastically complicates traditional detection and defense mechanisms. He highlights the shift this represents:

“The shift: Attackers no longer need to code everything manually. AI can generate new malicious variants on demand, making detection and defense far harder.”

Implications for Cybersecurity and Attackers

The implications of this AI-powered cybercrime are profound, according to Goswami. One of the most critical risks he points out is the democratization of advanced cyber threats. Previously, sophisticated ransomware attacks required significant coding expertise and resources.

Lowering the Barrier to Entry for Cybercriminals

Goswami argues that AI support significantly lowers the barrier to entry for individuals with less technical skill. This means that attackers who might not have the capability to manually develop complex malware can now launch advanced ransomware campaigns with AI assistance.

“The risk: Low-skilled attackers can now launch advanced ransomware campaigns with AI support.”

This accessibility could lead to an increase in the volume and sophistication of ransomware attacks, posing a greater challenge to organizations worldwide. The ability of AI to rapidly generate polymorphic code means that signature-based detection methods may become less effective, necessitating a move towards more advanced, behavior-based security solutions.

Preparing for Next-Generation Threats

In light of these evolving threats, Chirag Goswami, through his organization Cybernara, emphasizes the importance of proactive measures. He suggests that organizations need to prepare for these next-generation threats by implementing robust strategies.

According to Goswami, these strategies should include:

  • Proactive monitoring for unusual activities and potential AI-driven threats.
  • Ensuring strict compliance with security protocols.
  • Developing and practicing effective incident response plans tailored to AI-powered attacks.

Goswami concludes by inviting connections for those looking to bolster their resilience against AI-powered attacks, underscoring the urgent need for businesses to adapt their cybersecurity frameworks to address this new frontier of cybercrime.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on August 29, 2026 | View original post on LinkedIn →