New browser-only ransomware technique

New research from Check Point Research (CPR) reveals that modern large language models (LLMs) can now transform general malicious ideas into practical cyberattack scenarios, significantly reducing the technical level required to create new attacks.
deepseek llm hallucination browser ransomware
At the heart of the research is a new technique that researchers call Web Browser Only RansomwareThe attack is carried out exclusively through the browser, without the installation of an application, malware (APK), exploit or root privileges. Instead, it is based solely on social engineering and the abuse of legitimate functionality. File System Access API, which allows websites to access files after user approval.

The research shows that an attacker could present a seemingly innocent AI service – such as a photo enhancement app – asking the user for access to their images folder. With a single authorization, the website could gain the ability to read, modify or even encrypt the user’s files, without installing any software on the device.

See more articles from iGuRu.gr when you search for news on Google.

Of particular concern is the fact that this scenario is currently practically applicable mainly on Android devices using Chromium - based browsers , where photo folders are often a storage space for highly sensitive personal data, such as personal photos, identification documents, bank statements, medical records and professional materials.

As part of the research, Check Point analyzed nearly 3.000 files related to DeepSeek, of which 1.383 were classified as malicious or potentially dangerous. The analysis revealed that while the initial sample generated by the AI ​​was not fully functional, it contained a new attack idea, which the researchers were able to turn into a working proof-of-concept with minimal intervention.

Check Point notes that there is no evidence yet that this technique is already being used in real attacks. However, the finding highlights a significant change in the cyberthreat landscape: artificial intelligence is no longer limited to reproducing known techniques, but can combine existing capabilities in new ways, creating original attack scenarios that were previously considered mainly theoretical.

According to the researchers, the most important defense against these types of attacks is increased user attention when a browser requests access to folders or files on the device, as such requests should now be treated as critical security decisions and not as a normal web browsing action.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).