SatanLock is a ransomware group that emerged in April 2025 and quickly became visible through a high-volume leak-site operation. The group publicly listed numerous victims and was assessed among the more prevalent ransomware brands observed during that period. Reporting also indicated that many victims presented on its leak site had previously been claimed by other ransomware groups, raising questions about the originality and provenance of some of its victim claims. By July 2025, SatanLock announced a sudden shutdown of operations and leaked data associated with past victims. SatanLock operated as an extortion-focused ransomware actor centered on victim shaming and publication of stolen data through a leak site. Its known behavior supports the use of data-theft extortion and leak-site pressure tactics, and the group was associated with a ransomware-branded operation referred to as SatanLock V2 during its shutdown phase. Publicly available information in this context does not establish a reliable country of origin, specific national targeting pattern, or a clearly attributable state affiliation. The actor is best characterized as a financially motivated cybercriminal ransomware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with a sudden shutdown announcement (v2 branding referenced).
Satanlock was a ransomware group that operated for a short period, listing over 70 victims and leaking stolen data after shutting down.
SatanLock is a new ransomware group that has begun listing victims on its data leak site, indicating involvement in ransomware operations and data extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.