ailock

Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:57:03

Context

AiLock is a Ransomware-as-a-Service (RaaS) group first identified in March 2025. It employs a double-extortion approach—encrypting files and threatening to report breaches to regulators or share stolen data with competitors if the ransom isn’t paid. Victims have just 72 hours to respond and up to five days to pay; failure to pay results in data leaks and destruction of recovery tools. The ransomware appends the extension .AiLock to encrypted files, changes file icons to a green padlock with the “AiLock” name, and replaces the desktop wallpaper with a distinctive robot-skull logo. It employs a hybrid encryption scheme, combining ChaCha20 for file encryption with NTRUEncrypt for securing metadata, and uses a multi-threaded design (path-traversal and encryption threads with IOCP) for efficiency. While active campaigns and leak sites are confirmed, specific sectors, regions, and intrusion methods remain undisclosed in public sources.

Reports & references

  • ransomlook.io — Ailock (report)
  • fortra.com — Ailock Ransomware (report)
  • gbhackers.com — Ailock Ransomware Emerges With Hybrid Encryption Tactics (report)
  • medium.com — Detailed Analysis Of Ailock Ransomware 1D3263Beff15 (report)
  • s2w.inc — 871 (report)

External references