Check Point Research discovered a browser-native ransomware technique in a DeepSeek-attributed malicious sample. The attack abuses the File System Access API — a legitimate browser feature — to enumerate, exfiltrate, and encrypt local files entirely within the browser, requiring no native payload, no exploit, and no installation. The original sample was AI-generated and incomplete, but researchers confirmed that a working proof-of-concept could be built with minimal effort using modern LLMs. The technique is especially dangerous on Android (Chrome 132+), where a fake AI photo-enhancer lure can trick users into granting write access to their DCIM/photo directory. The research highlights how LLM hallucinations can inadvertently surface practical attack techniques by mapping malicious goals to real browser APIs, lowering the expertise barrier for operationalizing novel attack chains.