As cited
Copy frozen at (site build).
ransomware
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Researchers demonstrated a practical ransomware attack that operates entirely within a web browser on Android devices using the File System Access API, bypassing traditional malware defenses. The attack leverages social engineering through a fake image-enhancement workflow to trick users into granting file system permissions, enabling attackers to encrypt photos and other files. The research highlights how large language models like DeepSeek, with lower refusal rates for harmful requests than competitors, can convert malicious concepts into working attack code more easily than other AI platforms.
Why it matters: Android users and organizations supporting mobile workers face a new attack vector that circumvents app-based malware detection, requiring security awareness training and browser permission policy reviews to prevent social engineering exploitation of legitimate APIs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Researchers discovered that DeepSeek, a large language model (LLM), can generate working browser-based ransomware that exploits the File System Access application programming interface (API) in Google Chrome on Android devices. The technique uses social engineering to trick users into granting folder-level file access under the guise of an image enhancement app, then encrypts photos and personal files without requiring native code, browser exploits, or root access. DeepSeek's lower refusal rates for harmful requests and accessibility make it particularly attractive to threat actors compared to OpenAI or Anthropic models.
Why it matters: Android users and organizations managing mobile security should assess the risk of browser-based ransomware delivered via legitimate web interfaces, as this attack bypasses traditional app-based defenses and relies only on user permission prompts. Security teams need to monitor for file encryption activity on mobile devices and educate users about granting file system access permissions through browser prompts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Researchers discovered that DeepSeek, a large language model (LLM), can generate working browser-based ransomware that exploits the File System Access application programming interface (API) in Google Chrome on Android devices. The technique uses social engineering to trick users into granting folder-level file access under the guise of an image enhancement app, then encrypts photos and personal files without requiring native code, browser exploits, or root access. DeepSeek's lower refusal rates for harmful requests and accessibility make it particularly attractive to threat actors compared to OpenAI or Anthropic models.
Why it matters: Android users and organizations managing mobile security should assess the risk of browser-based ransomware delivered via legitimate web interfaces, as this attack bypasses traditional app-based defenses and relies only on user permission prompts. Security teams need to monitor for file encryption activity on mobile devices and educate users about granting file system access permissions through browser prompts.
- Source published
- First seen by Cybersecurity Tracker