LIVE · cybersecurity feed
Live wire

browser security

ransomwarehigh

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Researchers have demonstrated a novel ransomware technique that operates entirely within a web browser, bypassing the need for native installations or exploits. By leveraging the File System Access API in Chrome, specifically on Android, malicious websites can trick users into granting access to sensitive photo directories. This method, inspired by AI-generated concepts, uses social engineering tactics like fake image-enhancement tools to prompt users for permissions, enabling the browser-based ransomware to potentially encrypt or modify files.