Researchers have identified a ransomware technique that uses legitimate browser permissions to encrypt user files, illustrating how AI tools could lower the technical barrier for developing new forms of cyberattacks.

WHAT’S HAPPENING

Check Point Research says it discovered a Python-based ransomware proof of concept while analyzing files associated with DeepSeek.

The technique, described as In-Browser Ransomware, uses phishing or social engineering to convince a user to grant a website file-system access through the browser’s File System Access API.

Once permission is granted, malicious code could potentially encrypt accessible files directly through the browser rather than relying on a traditional malware installation or browser vulnerability.

Researchers said AI assistance appeared to make developing the technique possible with relatively limited expertise.

WHY IT MATTERS

Browsers increasingly function as gateways to local files, cloud applications, credentials, and workplace systems.

If attackers can abuse legitimate browser permissions instead of exploiting software vulnerabilities, some traditional security defenses may have less visibility into the initial attack.

AI coding systems could also make experimentation with these techniques easier, although the discovery does not establish that such attacks are already occurring at large scale.

WHO BENEFITS

Cybersecurity Teams — The research provides defenders with an early look at a potential attack method before widespread adoption.

Security Vendors — New browser-based threats could increase demand for monitoring and protection beyond traditional endpoint malware.

WHO LOSES

Organizations and Users — Successful social engineering could expose files even when browsers and operating systems are fully patched.

Traditional Security Models — Defenses focused primarily on malicious downloads and software exploits may need to account for abuse of legitimate permissions.

WHAT HAPPENS NEXT

Security researchers will watch for evidence that browser-based ransomware moves from experimentation into real-world campaigns.

Organizations may increasingly treat browser permissions—particularly access to local files—as part of endpoint security rather than simply a user convenience setting.

Stay Sharp

Subscribe to follow the Trend newsletter and more.

Have a tip or idea?

Pass along insights or story ideas on AI, startups, and business. Focused on signal over noise, impact over headlines. Facts. Trends. Consequences. Always.