Promptlock Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
22
occurrences
First Seen
November 5, 2025
Last Seen
July 8, 2026

Promptlock is a ransomware_group tracked across 16 threat clusters and 22 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity July 8, 2026.

Related Threat Clusters

  • JADEPUFFER: First Fully Autonomous AI Ransomware Attack Documented

    JADEPUFFER, an autonomous AI-driven ransomware, executed a complete extortion operation exploiting CVE-2025-3248. The attack began with a compromised Langflow instance, allowing the AI to gain initial access without…

    31 articles · Updated July 9, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1553 articles · Updated February 12, 2026
  • AI and Cybersecurity Risks Highlighted at Global Summits

    The India AI Impact Summit 2026 and BRICS Foreign Ministers' Meeting emphasized the dual nature of AI, presenting both opportunities for economic growth and significant cybersecurity risks. ESET's CEO discussed AI's…

    2 articles · Updated May 19, 2026
  • Surge in Cyberattacks Driven by AI-Generated Ransomware and NFC Exploits

    A significant increase in cyberattacks has been reported, with hackers utilizing AI-driven ransomware and NFC attacks. The newly discovered PromptLock ransomware dynamically generates malicious scripts, scanning and…

    2 articles · Updated January 8, 2026
  • Google Identifies AI-Driven Malware Families with Self-Modifying Capabilities

    Google's Threat Intelligence Group has discovered at least five new malware families that utilize artificial intelligence for self-modification during execution. This technique, referred to as 'just-in-time'…

    2 articles · Updated November 5, 2025
  • PromptSpy: First Android Malware Utilizing Generative AI Discovered

    ESET researchers have identified PromptSpy, the first Android malware to incorporate generative AI, specifically Google’s Gemini, in its execution flow. This malware utilizes AI to manipulate the user interface and…

    39 articles · Updated February 19, 2026
  • Retail Sector Targeted by Ransomware Exploiting Security Gaps

    Sophos reports that 46% of ransomware incidents in the retail sector stemmed from previously unknown security vulnerabilities. This highlights ongoing challenges in maintaining visibility and security within retail…

    7 articles · Updated December 1, 2025
  • Gemini AI Misused for Developing Self-Modifying Malware by Cybercriminals

    Nation-state actors and cybercrime groups are utilizing Gemini AI to create a 'Thinking Robot' malware module capable of rewriting its own code to evade detection. This development also includes an AI agent designed to…

    2 articles · Updated November 5, 2025
  • AI-Driven Ransomware Threatens Global Cybersecurity

    PromptLock, the first AI-driven ransomware, has emerged as a significant cybersecurity threat. This malware utilizes a dual-component system to autonomously generate unique scripts for each target, challenging…

    4 articles · Updated January 1, 2026
  • Debate on AI SOC Agents and Security Outcomes

    The discussion around AI Security Operations Centers (SOCs) is evolving, with Gartner's report highlighting the mainstream recognition of AI's potential in enhancing SOC functions. However, critiques emphasize that…

    52 articles · Updated November 16, 2025

Recent Intelligence Reports

  • JADEPUFFER: First Fully Autonomous AI Ransomware Attack | Let's Data Science — Letsdatascience · July 8, 2026
  • An AI Agent Just Pulled Off a Full Ransomware Attack—and It Didn't Save the Decryption Key — Finance.Biggo · July 3, 2026
  • India AI Impact Summit 2026 — www.globenewswire.com · May 19, 2026
  • Android PromptSpy malware harnesses Gemini for stealth — Securitybrief · February 20, 2026
  • ESET Research discovers PromptSpy, the first Android threat to use generative AI — Markets.Businessinsider · February 19, 2026
  • Android malware taps Gemini to navigate infected devices — Theregister · February 19, 2026
  • PromptSpy – First Known Android AI Malware Uses Google’s Gemini for Decision — Cybersecuritynews · February 19, 2026
  • PromptSpy Android malware may exploit Gemini AI — Computerweekly · February 19, 2026

CVSS v3.1 Breakdown