AiLock is a ransomware-as-a-service operation first identified in March 2025. It combines file encryption with data-theft extortion, using negotiation infrastructure and a leak site to pressure victims; it has also republished material associated with prior victims after resuming activity in 2026. The ransomware is implemented in C/C++ and uses ChaCha20 for file encryption, with NTRUEncrypt protecting associated metadata and encryption material. It employs multithreaded encryption, applies full or partial encryption according to file size, enumerates local drives and network shares, and can stop services, terminate processes, empty the recycle bin, alter victim-system visual settings, and remove itself. Defense-evasion features include XOR-obfuscated strings and dynamic API resolution. Reported victims span Japan, the United States, Spain, Italy, Mexico, France, Switzerland, and Germany, including organizations in manufacturing, construction, health care, retail, education, business services, and professional services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AiLock was listed among other ransomware groups observed in Japan during the first half of 2026.
Conducting a reported ransomware attack against Hamilton Company.
Conducted a ransomware attack against Morgan Services, a linen and uniform rental company.
Threat actor targeting professional services, with activity suggesting coordinated mass exploitation of a shared vulnerability and focus on confidential client data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.