← Back to articles
Governance6 MIN READ

AI Ransomware Is Here. Is Your SMB Ready?

ESET research shows AI-powered ransomware and faster phishing attacks are hitting SMBs hardest. Here's the security checklist every operator needs right now.

Alex Followell
Alex Followell
2026-09-23 · 6 min read
TL;DR

AI-powered ransomware is no longer theoretical. ESET's latest research confirms the first known AI-powered ransomware proof of concept (PromptLock) and the first Android malware using generative AI in its execution flow (PromptSpy). These aren't just faster attacks; they're smarter ones that adapt to your environment. Most SMBs don't have a security team large enough to keep pace, which means your checklist and your tooling need to close that gap before attackers find it.

What exactly is AI-powered ransomware and why should SMBs care?

AI-powered ransomware means the malware itself uses machine learning or generative AI to adapt its behavior, evade detection, or optimize its attack path in real time. This is not a future threat. ESET's research has identified PromptLock as the first known AI-powered ransomware proof of concept and PromptSpy as the first known Android malware to weave generative AI into its execution flow. For SMBs running lean IT, this changes the math on how fast you need to detect and respond.

Traditional ransomware followed predictable patterns. Security tools learned those patterns and flagged them. AI-powered variants can randomize behavior, generate convincing lures on the fly, and adjust based on the defenses they encounter. Your signature-based antivirus was not built for this.

How are attackers using AI agents to hit SMBs right now?

AI agents can automate reconnaissance, credential stuffing, and phishing at a scale and speed that was previously too expensive for attackers targeting small businesses. Where a human attacker might craft one spear-phishing email per hour, an AI agent can generate thousands of personalized, contextually accurate messages pulling from LinkedIn profiles, company websites, and public filings.

ESET's research highlights that the same AI tools democratizing productivity for legitimate businesses are lowering the barrier to entry for attackers. You no longer need to be a sophisticated threat actor to run a sophisticated campaign. A moderately skilled attacker with access to the right tools can now punch well above their weight class, and SMBs are the preferred target because they typically have weaker defenses than enterprises but more assets than individuals.

The threat surface for a 50-person company in 2025 looks a lot like the threat surface for a 500-person company in 2020. The attacks scaled down to you.

What does the actual risk look like for a small business?

According to Verizon's 2024 Data Breach Investigations Report, 68% of breaches involve a human element, and phishing remains the dominant initial access vector. AI is making phishing faster, cheaper, and harder to detect. Combine that with the emergence of AI-native malware like PromptLock, and the window between initial compromise and full encryption of your environment shrinks significantly.

For context on the financial damage: IBM's Cost of a Data Breach Report 2024 put the average cost of a breach for organizations with fewer than 500 employees at $3.31 million. Most SMBs do not have the cash reserves or cyber insurance coverage to absorb that. This is an existential threat for many operators, not just a bad quarter.

Which specific threats from ESET's research matter most for SMBs?

Three findings from ESET's reporting deserve your attention:

PromptLock (AI-powered ransomware PoC): The first known ransomware proof of concept using AI to modify its behavior. It is a proof of concept today. Criminal groups have a track record of weaponizing research-level threats within 12 to 24 months.

PromptSpy (Android malware with generative AI): The first known Android malware to integrate generative AI into its execution flow. If your team uses Android devices for work, email, or two-factor authentication apps, this is directly relevant to your attack surface.

AI-accelerated old attacks: ESET also notes that AI is turbocharging established attack types. Social engineering, credential theft, and business email compromise are all getting faster and more convincing. The attacks your team already struggles to catch are getting harder to catch.

What should your SMB security checklist include right now?

This is not an exhaustive list, but these are the highest-leverage actions given what ESET's research shows:

Identity and access controls

  • Enforce phishing-resistant MFA (hardware keys or passkey-based) on every external-facing system. SMS-based MFA is better than nothing but is no longer sufficient.
  • Audit privileged accounts quarterly. Attackers go for admin credentials first.
  • Implement conditional access policies that flag logins from unusual locations or devices.

Endpoint and email protection

Backup and recovery

  • Maintain offline or immutable backups. AI-powered ransomware can move fast enough to encrypt cloud-synced files before you notice. Offline backups are your last line of defense.
  • Test your restore process at least once per quarter. A backup you have never restored is a backup you do not actually have.

Staff training calibrated to AI threats

  • Update phishing simulations to include AI-generated content. Generic fake-login-page tests are not representative of what your team will actually see.
  • Train employees specifically on voice phishing (vishing) and deepfake video calls, which are now viable attack vectors for even moderately funded criminal groups.

Governance and incident response

  • Document an incident response playbook before you need it. Even a one-page decision tree for "what do we do if ransomware hits" saves hours in a crisis.
  • Define who has authority to pull the plug on systems, who contacts your cyber insurer, and who communicates externally.

| Control | Why it matters now | Minimum viable version | |---|---|---| | Phishing-resistant MFA | AI phishing bypasses SMS codes | YubiKey or passkeys on critical accounts | | Behavioral EDR | AI malware evades signature detection | Defender for Business ($3/user/mo) | | Immutable backups | Ransomware encrypts cloud-synced files | Backblaze or Wasabi with object lock | | AI email filtering | Personalized phishing at scale | Microsoft Defender or Proofpoint Essentials | | IR playbook | Reduces breach cost and decision fatigue | One-page document, reviewed quarterly |

Does AI security tooling actually help SMBs or is it just vendor marketing?

Some of it is real, some of it is badge-slapping "AI" on existing features. The meaningful applications for SMBs right now are behavioral anomaly detection in EDR tools, AI-assisted email triage that surfaces suspicious patterns humans miss, and automated threat intel correlation that would otherwise require a full security operations center. The key question to ask any vendor: what specific model or technique powers this feature and what does it actually detect that your previous tool missed? Vendors who cannot answer that concretely are selling marketing, not security.

What we'd actually do

  • Run an honest gap assessment this week. Pull your current tooling list and check it against the table above. If you are still on signature-based AV and SMS MFA, those are your first two replacements, in that order.
  • Get your backup tested before anything else. Governance and tooling upgrades take time. A verified, offline backup is the one control that limits catastrophic downside while you improve everything else. Do this in the next 30 days.
  • Bring your leadership team into the conversation. AI-powered attacks are a board-level risk, not just an IT problem. If your executive team does not understand that PromptLock-style threats are coming and that response time now matters in minutes rather than hours, they cannot make good resourcing decisions. Join the community at skool.com/aiforbusiness to work through governance frameworks with other operators who are navigating the same decisions.

FAQ

What is PromptLock and should my SMB be worried about it?

PromptLock is the first known AI-powered ransomware proof of concept, identified in ESET's research. It is not yet in widespread circulation, but proof-of-concept threats typically get weaponized by criminal groups within 12 to 24 months. Now is the right time to upgrade your endpoint detection to behavioral tools that can catch it when it arrives.

How is AI making phishing attacks harder to catch?

AI lets attackers generate personalized, contextually accurate phishing messages at scale, pulling from public data like LinkedIn profiles and company websites. These messages lack the spelling errors and generic language that traditional filters flag. AI-assisted email security tools that score messages on behavioral signals, not just known-bad content, are the practical countermeasure.

What is the single highest-priority security action for an SMB with limited budget?

Verified, immutable backups. If ransomware hits and you can restore cleanly, the attack becomes a disruption rather than a catastrophe. Offline or object-locked cloud backups protect you even when every other control fails. After that, move to phishing-resistant MFA and behavioral endpoint detection.

JOIN THE COMMUNITY

Want this running in your business?

The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.

  • Weekly Q&A with Alex and Cameron
  • Templates and frameworks you can steal
  • Real builds, running in real businesses
Join skool.com/aiforbusiness ↗