Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ailock

Description

AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid. Known victims: 31 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

AiLock is a medium-sophistication ransomware operation known since 2015 but became active in early 2025. It uses AI-assisted encryption and double-extortion tactics to target organizations for financial gain. The group has successfully targeted multiple victims across various industries, including retail, healthcare, education, and technology.

Goals & Targeting

AiLock's primary motivation is financial gain, achieved through ransom payments and affiliate recruitment fees. The group targets industries with potentially high-value assets or sensitive data, such as retail, healthcare, education, and technology. Its broad targeting approach suggests it seeks the maximum number of victims rather than focusing on specific sectors or geographies.

Enhanced Description

AiLock is a ransomware operation that emerged in April 2025 and quickly gained notoriety due to its advanced encryption methods and aggressive tactics. It employs a hybrid encryption scheme combining ChaCha20 and NTRUEncrypt algorithms, making decryption challenging without the specific private keys used. The group leverages double-extortion techniques, threatening to publish victim data unless ransoms are paid in cryptocurrency. AiLock actively recruits affiliates and operates with a structured business model, offering its ransomware as a service (RaaS). This operation has targeted over 31 victims globally, including entities such as Site Design Group, Raich Sp. z o.o., and Mother's Market & Kitchen. The group's persistence in operations is evidenced by its activity from April 2015 to July 2026.

Key Capabilities

  • Advanced encryption using ChaCha20/NTRUEncrypt algorithms
  • Double-extortion tactics to increase pressure on victims
  • AI-assisted ransomware operations
  • Ransomware-as-a-Service (RaaS) model for affiliate recruitment
  • Persistent and long-term campaign activity

MITRE ATT&CK Tactics

Defense Evasion
Execution

ATT&CK Techniques

T1059.003
T1078.002

Software / Tooling

AI-assisted ransomware (custom)

Campaigns & Victims

AiLock has demonstrated a consistent operational tempo, targeting small to medium-sized businesses across various sectors. Notable campaigns include attacks on healthcare providers, educational institutions, and technology companies. The group's victims span regions including North America, Europe, and Asia, indicating a global targeting strategy.

IOC Patterns

  • Ransomware infection via phishing emails with malicious links or attachments
  • Double-extortion tactics involving data theft and encryption
  • Use of hybrid encryption algorithms in malware

Recommended Actions

  • Implement robust network monitoring to detect suspicious activity.
  • Regularly back up critical systems and secure backups offline.
  • Educate employees on phishing and ransomware threats.
  • Segregate sensitive data from general networks.
  • Monitor for cryptocurrency transactions linked to known ransomware groups.

Suggested Tags

Ransomware
Extortion
AI-Enabled Threats

Confidence Assessment

High confidence in AiLock's operational capabilities and targeting patterns due to multiple confirmed victims. However, specific details about targeted sectors or geographies remain unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

47

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Extortion
AI-Enabled Threats

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 29, 2015
Last Seen
Jul 15, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.