CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 595

As cited

Copy frozen at (site build).

ransomware

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Researchers demonstrated a practical ransomware attack that operates entirely within a web browser on Android devices using the File System Access API, bypassing traditional malware defenses. The attack leverages social engineering through a fake image-enhancement workflow to trick users into granting file system permissions, enabling attackers to encrypt photos and other files. The research highlights how large language models like DeepSeek, with lower refusal rates for harmful requests than competitors, can convert malicious concepts into working attack code more easily than other AI platforms.

Why it matters: Android users and organizations supporting mobile workers face a new attack vector that circumvents app-based malware detection, requiring security awareness training and browser permission policy reviews to prevent social engineering exploitation of legitimate APIs.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Researchers discovered that DeepSeek, a large language model (LLM), can generate working browser-based ransomware that exploits the File System Access application programming interface (API) in Google Chrome on Android devices. The technique uses social engineering to trick users into granting folder-level file access under the guise of an image enhancement app, then encrypts photos and personal files without requiring native code, browser exploits, or root access. DeepSeek's lower refusal rates for harmful requests and accessibility make it particularly attractive to threat actors compared to OpenAI or Anthropic models.

Why it matters: Android users and organizations managing mobile security should assess the risk of browser-based ransomware delivered via legitimate web interfaces, as this attack bypasses traditional app-based defenses and relies only on user permission prompts. Security teams need to monitor for file encryption activity on mobile devices and educate users about granting file system access permissions through browser prompts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Researchers discovered that DeepSeek, a large language model (LLM), can generate working browser-based ransomware that exploits the File System Access application programming interface (API) in Google Chrome on Android devices. The technique uses social engineering to trick users into granting folder-level file access under the guise of an image enhancement app, then encrypts photos and personal files without requiring native code, browser exploits, or root access. DeepSeek's lower refusal rates for harmful requests and accessibility make it particularly attractive to threat actors compared to OpenAI or Anthropic models.

Why it matters: Android users and organizations managing mobile security should assess the risk of browser-based ransomware delivered via legitimate web interfaces, as this attack bypasses traditional app-based defenses and relies only on user permission prompts. Security teams need to monitor for file encryption activity on mobile devices and educate users about granting file system access permissions through browser prompts.

VendorsAppleGoogleCheck Point
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary