AiLock is a ransomware-as-a-service operation first publicly identified in March 2025. The group conducts extortion through a negotiation portal and a data leak site, indicating a double-extortion model in which victims face both encryption and threatened publication of stolen data. Reporting also indicates the group resumed activity in 2026 and republished information related to prior victims. Known aliases include ailock and ailock_ransomware_group. AiLock has targeted organizations across multiple countries, including Japan, the United States, Spain, Germany, France, Switzerland, Italy, and Mexico. Observed victims span construction and infrastructure, manufacturing, health care, education, retail, and business services, indicating broad opportunistic targeting rather than a narrowly specialized victimology. The ransomware is written in C/C++ and uses ChaCha20 for file encryption, with NTRUEncrypt used to protect metadata and encryption material. It supports multithreaded encryption using I/O Completion Ports and separates path traversal from encryption logic. Reported behavior includes full encryption of smaller files and partial encryption of larger files, enumeration of local drives and network shares, dropping ransom notes in affected directories, and appending a dedicated extension to encrypted files. Additional functionality includes dynamic API resolution, XOR-based string obfuscation, configuration decryption and integrity checks, service stopping, process termination, recycle-bin clearing, desktop and icon modification, mutex-based execution control, and optional self-deletion. These behaviors reflect mature ransomware tradecraft focused on efficient encryption, operational resilience, and defense evasion. Based on directly supported reporting, AiLock is best characterized as a financially motivated cybercriminal ransomware actor. No high-confidence attribution to a nation-state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Yaomasa, a Japanese supermarket chain.
Conducting a ransomware attack resulting in a data breach against DAISEN in Japan.
Conducting a ransomware attack resulting in a data breach against Ferrovial.
Conducting a ransomware attack against WBF Construction.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.