AiLock

AiLock — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

AiLockConfidence: Medium

Ransomware (RaaS)

Motivation: Financial

1Attributed Breaches Circulating
MediumAttribution Confidence
Ransomware (RaaS)Actor Type

Overview

Threatens to report breaches to regulators or hand data to competitors if unpaid, giving victims a 72-hour to 5-day window, first identified March 2025. Uses hybrid encryption (ChaCha20 for files, NTRUEncrypt for metadata) and a multithreaded design.

Tactics, Targeting & TTPs

Hybrid encryption (ChaCha20 for files, NTRUEncrypt for metadata); multithreaded design.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation