Check Point Research reported that an AI-assisted ransomware technique can be turned into a practical browser-only attack by abusing the File System Access API in Chromium-based browsers. The research began with analysis of a DeepSeek-attributed sample dubbed InfernoGrabber, which paired a fake AI image-enhancement lure with browser code intended to access local files. Although the original sample contained incomplete and hallucinatory code, researchers found it pointed to a viable attack path in which a malicious website requests user-approved access to files, then reads, modifies, exfiltrates, and potentially encrypts them without deploying a native payload or exploiting the browser.
The team said the risk is most acute on Android, where Chrome exposes picker-based file access to photo directories such as DCIM, making a fake photo-processing site a plausible delivery mechanism. Using modern LLM prompting, the researchers produced a working proof of concept that encrypted files in selected image folders without requiring an APK install, root access, or a browser exploit. Check Point said it had not observed this exact technique being widely used in the wild, but warned that frontier AI is lowering the skill barrier for attackers to operationalize previously theoretical browser abuse methods.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Using modern LLM prompting, Check Point Research turned the concept into a working proof of concept that encrypted files in selected image directories through the browser. The technique required no native payload, browser exploit, APK installation, or root access, with the highest practical risk described on Android Chrome.
Check Point Research analyzed a DeepSeek-attributed malicious sample called InfernoGrabber and found it tied a fake AI image-enhancement lure to the File System Access API, though much of the code was incomplete or hallucinatory. The researchers reported no evidence that this exact technique had been widely used in the wild at the time of analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceresearch.checkpoint.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.