A ransomware attack used to mean encrypted files, a ransom note, and a payout demand. Researchers at NYU’s Tandon School of Engineering recently published PromptLock, the first functional ransomware powered end-to-end by large language models (LLMs). It signals the arrival of Ransomware 3.0, changing how IT directors and security managers need to think about cybersecurity defense.
From Traditional Ransomware to Ransomware 3.0
Traditional ransomware ran on hardcoded scripts. Hackers wrote the encryption routine, picked targets, and triggered the malware. Ransomware 2.0 added double and triple extortion, in which attackers exfiltrate data before encrypting it, then threaten public release for a higher ransom. Ransomware-as-a-service (RaaS) commercialized the model, enabling bad actors with no coding skills to access packaged ransomware tools.
Ransomware 3.0 is the next step. It runs on AI, with LLMs and AI systems orchestrating the attack from start to finish.
What Makes Ransomware 3.0 Different?
The Tandon team’s proof-of-concept showed all four phases of ransomware running autonomously. Malicious code uses a prompt to drive an LLM through reconnaissance, identifying valuable files such as financial records and source code, encrypting them, and generating ransom notes tailored to each target.
Three properties stand out. The code is polymorphic, so the AI rewrites itself to evade signature-based detection. It operates autonomously once dropped, which speeds up attack timelines. Ransom notes can include personalized extortion language pulled from files the AI just read, raising psychological pressure on the victim.
How Attackers Use AI to Expand the Cyber Threat Surface
AI-powered tooling lowers the cost of every attacker workflow. Spear phishing emails written by LLMs slip past multi-factor authentication (MFA) challenges more often when paired with social engineering. AI-driven attackers can deceive employees and infiltrate cloud admin accounts. They can also pivot into industrial control systems, where a single foothold can disrupt operations across enterprise servers and SaaS environments.
The cybercrime ecosystem has already absorbed these techniques. RaaS operators advertise AI-augmented kits. Espionage groups linked to government agencies are testing similar capabilities. The sophistication gap between top-tier and entry-level cybercriminals is closing. The result is more frequent ransomware attacks and a wider range of cybersecurity threats.
New Defenses for an AI-Powered Threat
Operational defense against Ransomware 3.0 builds on controls that hold for Ransomware 2.0, then adds new layers. Strong authentication is foundational. Phishing-resistant MFA, biometric checks for admin access, and conditional access policies that gate SaaS data access are the starting point.
Priorities for security managers and IT directors:
- Maintain immutable backups stored offline, tested for restore time, and isolated from production credentials
- Harden every internet-facing asset, including firewall rules, exposed enterprise servers, and any vulnerability that allows initial access
- Add a quantitative threat model so your team ranks exposure by likelihood and impact
- Feed real-time threat intelligence into detection so AI-driven attacker behavior surfaces before encryption begins
These controls work better when you continuously see the full external attack surface. TITAN Secure maps Internet Intelligence data — active threat actor signals, adversary infrastructure, and active infections — directly to your vendor ecosystem, catching reconnaissance signals and exploit attempts the moment they appear.
Why Third-Party Risk Amplifies Ransomware 3.0 Exposure
Most ransomware attacks now move through a vendor or partner. Our 2025 Global Third-Party Breach Report found that 35.5% of breaches involved third parties, and AI-powered attackers will press that advantage. Cybercriminals can run autonomous reconnaissance across an entire vendor base, find the weakest link, and pivot inward.
Periodic questionnaires cannot keep pace with attackers who move in hours. TITAN Watch gives you continuous visibility into vendor security posture across 4.1 billion scanned IP addresses, so a new vulnerability in a critical supplier surfaces in real time. TITAN Assess automates the end-to-end third-party risk workflow for teams that need to validate controls and demonstrate compliance.
Building Stronger Security Against Ransomware 3.0
Ransomware 3.0 is no longer a future hypothetical. The proof-of-concept exists, and the new threat is already shaping how attackers operate.
Pairing stronger authentication, immutable backups, hardened attack surfaces, and continuous third-party monitoring will help you adapt best to the shift. SecurityScorecard’s TITAN AI platform gives you a seamless, real-time view of cyber risk across your environment and all vendors.
Request a demo to see how it works.
Frequently Asked Questions
What Is Ransomware 3.0?
Ransomware 3.0 is the latest stage of ransomware, where artificial intelligence and large language models drive the attack workflow autonomously. The Tandon School of Engineering’s proof-of-concept PromptLock is the first public example.
How Is Ransomware 3.0 Different From Ransomware 2.0?
Ransomware 2.0 added data theft and triple extortion to traditional ransomware. Ransomware 3.0 adds AI orchestration. The malware is polymorphic, runs without human direction, and pulls personalized extortion content from each victim’s files.
Can Existing Defenses Stop AI-Powered Ransomware?
MFA, immutable backups, hardened firewall rules, and patched enterprise servers remain core defenses. AI-powered ransomware accelerates every attack phase, so teams need real-time threat intelligence and continuous monitoring on top.
How Can Security Teams Prepare for Ransomware 3.0?
Start with strong authentication, an immutable backup strategy, and continuous attack surface visibility. Then add a quantitative threat model and AI-aware detection so reconnaissance and exploit activity is caught before encryption fires.