Check Point Research
Read post

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Check Point Research discovered a browser-native ransomware technique in a DeepSeek-attributed malicious sample. The attack abuses the File System Access API — a legitimate browser feature — to enumerate, exfiltrate, and encrypt local files entirely within the browser, requiring no native payload, no exploit, and no installation. The original sample was AI-generated and incomplete, but researchers confirmed that a working proof-of-concept could be built with minimal effort using modern LLMs. The technique is especially dangerous on Android (Chrome 132+), where a fake AI photo-enhancer lure can trick users into granting write access to their DCIM/photo directory. The research highlights how LLM hallucinations can inadvertently surface practical attack techniques by mapping malicious goals to real browser APIs, lowering the expertise barrier for operationalizing novel attack chains.

    #security#ransomware#deepseek
Jul 01•16m read time•From research.checkpoint.com
Post cover image
Table of contents
Key TakeawaysIntroductionA Noisy Sample With One Important IdeaFrom Hallucinated Scaffold to Working PoCIn-Browser Ransomware on AndroidPractical Recommendations for UsersConclusion
171 Impressions
Check Point Research's image
Check Point Research

CP Research Blog offers insights, tutorials, and updates on competitive programming, algorithms, and...

209 Followers

•

148 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard