Research · curated 22 Jul 2026

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique - Check Point Research

Coverage timeline

1 Jul 2026checkpoint.comprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

The research shows LLMs can independently design and implement novel, workable attack paths that have not yet appeared in the wild, lowering the barrier for browser-only ransomware against high-value personal data.

Check Point Research (Alexey Bukhteyev) describes how DeepSeek turned an unrealistic AI-generated browser-malware hallucination into a plausible browser-native ransomware technique that abuses Chrome's File System Access API. The demonstrated PoC uses a fake AI image-enhancement workflow to socially engineer users into granting folder-level access to photo directories on Android, requiring no native payload, APK install, browser exploit, or root.