AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid. Known victims: 31 1 ransom note(s) on file
Objectives
Executive Summary
AiLock is a medium-sophistication ransomware operation known since 2015 but became active in early 2025. It uses AI-assisted encryption and double-extortion tactics to target organizations for financial gain. The group has successfully targeted multiple victims across various industries, including retail, healthcare, education, and technology.
Goals & Targeting
AiLock's primary motivation is financial gain, achieved through ransom payments and affiliate recruitment fees. The group targets industries with potentially high-value assets or sensitive data, such as retail, healthcare, education, and technology. Its broad targeting approach suggests it seeks the maximum number of victims rather than focusing on specific sectors or geographies.
Enhanced Description
AiLock is a ransomware operation that emerged in April 2025 and quickly gained notoriety due to its advanced encryption methods and aggressive tactics. It employs a hybrid encryption scheme combining ChaCha20 and NTRUEncrypt algorithms, making decryption challenging without the specific private keys used. The group leverages double-extortion techniques, threatening to publish victim data unless ransoms are paid in cryptocurrency. AiLock actively recruits affiliates and operates with a structured business model, offering its ransomware as a service (RaaS). This operation has targeted over 31 victims globally, including entities such as Site Design Group, Raich Sp. z o.o., and Mother's Market & Kitchen. The group's persistence in operations is evidenced by its activity from April 2015 to July 2026.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
AiLock has demonstrated a consistent operational tempo, targeting small to medium-sized businesses across various sectors. Notable campaigns include attacks on healthcare providers, educational institutions, and technology companies. The group's victims span regions including North America, Europe, and Asia, indicating a global targeting strategy.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in AiLock's operational capabilities and targeting patterns due to multiple confirmed victims. However, specific details about targeted sectors or geographies remain unclear.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
47
Campaigns
2
IOCs
0
Observed Data
0
Tactics