Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

SEC and CFTC crypto relief: tokenized stocks and derivatives

September 18, 2026

TrustPlus AI Wins Excellence in Risk Management and Compliance Award at FinTech Week Awards & Expo Singapore 2026

September 18, 2026

Digital Collectibles and AI Stocks Drive Growth

September 18, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»AI-Generated Lcryx Ransomware Discovered in Cryptomining Botnet
AI-Generated Lcryx Ransomware Discovered in Cryptomining Botnet
Security and Privacy

AI-Generated Lcryx Ransomware Discovered in Cryptomining Botnet

July 21, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A cryptomining botnet that has been active since 2019 has added a likely AI-generated ransomware to its operations.

New analysis by FortiCNAPP team, part of FortiGuard Labs, has identified the first incident of an overlap between H2miner and Lcryx ransomware.

The team uncovered this link during an investigation into a cluster of virtual private servers (VPS) used for mining Monero (a type of cryptocurrency).

The investigation uncovered samples associated with prior H2miner campaigns that were documented in 2020 but have since been updated with new configurations.

The FortiCNAPP team also identified a new variant of the Lcryx ransomware, dubbed “Lcrypt0rx.” Lcryx is a VBScript-based ransomware strain first observed in November 2024.

It was assessed that Lcrypt0rx lacks the sophistication of more advanced ransomware families. However, it introduces distinct techniques for degrading system usability, UI interference and redundant embedded scripts.

It also bundles commercially available hack tools and infostealers, expanding its functionality beyond simple encryption.

FortiCNAPP said that the ransomware family exhibits several unusual characteristics that suggest it may have been generated using AI.

AI-Generated Lcryx Ransomware Harbors Several Flaws

The FortiCNAPP team said they have observed the growing adoption of large language models (LLMs) by threat actors in recent years.

However, this method of ransomware development has led to some critical flaws and illogical behavior within the script. It is these indicators which have led the team to suspect the Lcryx family of ransomware was generated using AI.

For instance, multiple functions are repeated throughout the script with no clear reason, suggesting automated code generation without optimization.

See also  Crypto-Exchange Used to Launder Ransomware Transactions Dismantled

There is also evidence of flawed encryption logic, redundant object creation and malformed syntax within the ransomware.

The script also conducts illogical behaviors like attempting to open encrypted files in Notepad, which FortiCNAPP noted has no practical function and makes no operational sense.

Even the ransom note URL has errors. The .onion address in the ransom note (http://lcryptordecrypt7xfzq5tclm9jzpwq72uofgy2znkdsxm54zbcu2yid[.]onion) does not conform to valid TOR address specifications. It may have been a placeholder during a transition from v2 to v3 onion services.

Antivirus disabling functionality is also shown to be ineffective, as the methods to disable Bitdefender and Kaspersky antivirus products are incorrect and are likely LLM hallucinations.

Read more about the use of LLMs for malware development: Cybercriminals Eye DeepSeek, Alibaba LLMs for Malware Development

Examining the H2miner-Lcryx Connection

The operational overlap between H2miner and Lcryx could indicate collaboration between the operators to maximize financial gain.

However, there are other possibilities for the joining of force.

First, H2miner operators could also have developed Lcrypt0rx to increase profits.

Alternatively, H2miner operators could be reusing Lcrypt0rx to conduct mining operations while shifting the blame.

The FortiCNAPP team concluded: “The campaign reflects a broader trend: the commodification of cybercrime, where access to prebuilt tools, LLM-generated code, and cheap infrastructure lowers the barrier to entry, enabling even low-skill actors to launch high-impact campaigns.”

Source link

AIGenerated Botnet Cryptomining Discovered Lcryx Ransomware
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

White Hats Used Anthropic’s Claude to Break Into OpenAI in 72 Hours

September 18, 2026

Crypto Wallet Maker DCENT Tells Users to Get Their Coins Out

September 16, 2026

Uniswap v4 hooks bait DeFi traders with fake swap quotes

September 16, 2026

Swiss Bitcoin Pay Just Went Dark After a Mysterious Intruder

September 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

The Rise of SocialFi: How Its Changing the Landscape of Social Media

May 27, 2024

Alephium Joins Mises Browser via Blockflow DAO Partnership

May 2, 2024

Atriv Partners with Flare to Accelerate its AI Digital Art and NFT Ecosystem

June 22, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

SEC and CFTC crypto relief: tokenized stocks and derivatives

September 18, 2026

TrustPlus AI Wins Excellence in Risk Management and Compliance Award at FinTech Week Awards & Expo Singapore 2026

September 18, 2026

Digital Collectibles and AI Stocks Drive Growth

September 18, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$80,868.005.64%
  • ethereumEthereum(ETH)$2,578.424.73%
  • tetherTether(USDT)$1.000.03%
  • binancecoinBNB(BNB)$760.784.87%
  • rippleXRP(XRP)$1.407.11%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$110.689.34%
  • tronTRON(TRX)$0.3390651.43%
  • zcashZcash(ZEC)$1,486.453.96%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.09%