Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AiLock ransomware is written in C/C++ language, and appends the extension(.AiLock) to the encrypted files and drops a ransom note called Readme.txt in the directory path of the encrypted files.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware actor mentioned as aggressively targeting professional services and client-confidential data, with activity pattern suggesting mass exploitation of a shared vulnerability.
Ransomware actor mentioned as aggressively targeting professional services and client-confidential data, with activity pattern suggesting mass exploitation of a shared vulnerability.
AiLock is a ransomware family first reported in March 2025. It encrypts files, appends the .AiLock extension, drops a Readme.txt ransom note, uses ChaCha20 for file encryption and NTRUEncrypt for protecting metadata, scans local drives and network shares, stops services and kills processes to maximize encryption, empties the recycle bin, changes wallpaper and file icons, and supports self-deletion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.