Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
released on 2026-07-01 @ 11:58:56 AM
Check Point Research discovered a novel browser-native ransomware technique that emerged from AI-generated code attributed to DeepSeek. The attack leverages the File System Access API in Chromium browsers to encrypt files without requiring native payloads, exploits, or app installations. A malicious sample disguised as an AI image upscaler was analyzed, revealing how LLMs can connect theoretical platform risks to practical attack workflows. The technique is particularly concerning on Android, where Chrome allows web pages to access photo directories after user approval through legitimate permission prompts. By using social engineering with a fake AI enhancement tool, attackers can persuade victims to grant folder-level access, enabling file exfiltration and encryption entirely within the browser. This demonstrates how frontier AI models can autonomously design novel attack chains by reasoning across existing knowledge.