Automatically translated.View original post

ESET warns of AI-driven malware threat

ESET warns of threat from AI-driven malware and fast-growing ransomware economy

The cybersecurity landscape has reached a critical turning point as artificial intelligence (AI) is moving from a theoretical threat to an active reality.

In the second half of the 2025 threat report, ESET researchers documented shocking changes in the way attackers work, revealing that AI-driven malware is no longer a distant problem, but a threat that is currently targeting systems around the world.

The emergence of AI-driven threats marks a fundamental change in the complexity of attacks. Today's attackers use machine learning models to generate malicious code adapted to each victim's environment, making traditional defense mechanisms increasingly inefficient.

This change represents the convergence of two ever-separate threats: advanced malware development and artificial intelligence capabilities.

ESET analysts identified PromptLock, the first known AI-powered ransomware, discovered in the second half of 2025. This malware operates through a unique two-component architecture that fundamentally changes the way ransomware works.

The static core module, written in the Go language, communicates directly with the server running the AI model and contains pre-written notification messages; these notification messages instruct the AI to create dynamic Lua scripts, which are then executed on the attacked system without prior writing by the developer.

Adaptive capacity

The technical complexity of PromptLock lies in its adaptability; unlike traditional ransomware that follows a predefined pattern, PromptLock uses an AI model to create unique scripts for file system exploration, data authentication, data retrieval, and encryption.

The malware automatically scans the victim's system and freely decides whether to retrieve, encrypt files, or destroy data based on what it finds.

To maintain performance, PromptLock incorporates a feedback circuit to verify the authenticity of the code generated by the AI. When the Lua script runs, the malware records the operation and sends it back to the AI model for evaluation.

If the code does not work properly, the model is instructed to modify the script based on feedback before running the modified version again; this iterative process ensures reliability despite the uncertain nature of the language model.

The impact is not limited to PromptLock; ESET researchers have identified other AI-driven threats, including PromptFlux, which prompted Gemini's AI model to rewrite the dropper's original code so it could remain; and PromptSteel, which generates Windows commands to extract archives from the victim's device.

The ransomware-as-a-service market is also growing rapidly; the number of victims publicly reported on websites that disclose leaks already exceeds the 2024 total before the end of the year, with a 40 percent year-on-year increase forecast.

Qilin and Akira currently dominate the ransomware market, while the emerging Warlock Group has introduced dangerous evasion techniques that avoid destination detection tools.

The convergence of AI-driven attacks and a booming ransomware economy, has made global enterprises desperately needed for security urgency.

# Trending # Lemon 8 Howtoo # Drug sign with lemon8 # lemon 8 diary # freedomhack

1/23 Edited to

... Read moreจากประสบการณ์จริงในการรับมือกับภัยคุกคามไซเบอร์ในองค์กรของผม พบว่าเทคโนโลยี AI ที่ถูกนำมาใช้ในมัลแวร์ยุคใหม่ มีความซับซ้อนและยืดหยุ่นกว่าที่คิดไว้มาก การที่มัลแวร์ เช่น PromptLock สามารถใช้โมเดล AI สร้างสคริปต์ Lua แบบไดนามิก ทำให้วิธีการตรวจจับแบบเดิมๆ ไม่สามารถตอบสนองได้ทัน และความสามารถในการสแกนระบบอย่างอัตโนมัติพร้อมประเมินสถานการณ์ก่อนจะดำเนินการต่างๆ เช่น การเข้ารหัสหรือดึงข้อมูล ถือเป็นจุดเปลี่ยนครั้งใหญ่ นอกจากนี้ การทำงานแบบวงจรป้อนกลับเพื่อประเมินความถูกต้องของโค้ด ช่วยเสริมความน่าเชื่อถือของการโจมตี ส่งผลให้มัลแวร์มีประสิทธิภาพสูงขึ้นและหลบเลี่ยงมาตรการป้องกันได้ดีขึ้นมาก การสังเกตการณ์จากเหตุการณ์จริงพบว่าองค์กรขนาดกลางและเล็กมักจะเป็นเป้าเนื่องจากระบบความปลอดภัยยังไม่แข็งแกร่งเพียงพอ เท่าที่เคยติดตามสถานการณ์ พบว่าเศรษฐกิจแรนซัมแวร์เติบโตขึ้นอย่างรวดเร็วโดยเฉพาะ ransomware-as-a-service ที่เปิดโอกาสให้กลุ่มโจรไซเบอร์รายเล็กๆ สามารถเข้าร่วมทำธุรกิจผิดกฎหมายนี้ได้ ทำให้ปริมาณเหยื่อและความเสียหายมีแนวโน้มเพิ่มขึ้นโดยต่อเนื่อง ด้วยเหตุนี้ ผมจึงแนะนำให้ทุกองค์กรเร่งปรับปรุงระบบความปลอดภัยทางไซเบอร์ โดยเฉพาะการใช้เทคโนโลยีตรวจจับภัยคุกคามที่ใช้ AI มาช่วยเสริมการวิเคราะห์พฤติกรรมของมัลแวร์ และฝึกอบรมพนักงานให้ระมัดระวังกับอีเมลหรือไฟล์ที่น่าสงสัยอย่างเคร่งครัด การเสริมสร้างความตระหนักรู้และการอัปเดตมาตรการป้องกันอย่างต่อเนื่อง ถือเป็นกุญแจสำคัญที่จะช่วยให้องค์กรสามารถรับมือกับภัยคุกคามยุคใหม่ที่ซับซ้อนและปรับตัวได้อย่างรวดเร็วนี้ได้ดียิ่งขึ้น