ESET discovers AI-assisted ransomware using Ollama API

ESET researchers report an AI-assisted ransomware family referred to as PromptLock. It leverages a locally hosted LLM through the Ollama API to generate Lua scripts on the host in real time, reducing command-and-control dependencies. For Incident Response, collection should include Ollama installations, model artefacts and transient Lua files; traditional network indicators alone may be insufficient. Red Team and Pen Test exercises should incorporate on-device LLM behaviours to validate controls that restrict unapproved model runtimes and script execution. https://lnkd.in/gw3UiV7U #IncidentResponse #RedTeam #PenTesting #Ollama #Lua #Ransomware

  • No alternative text description for this image

To view or add a comment, sign in

Explore content categories