Alphalocker Ransomware
TrackedThreat actor group tracked in the global ransomware database · Last disclosure: Feb 28, 2026
ThreatAI Analysis
Compiled from the ransomware.live profile for Alphalocker and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Alphalocker is a ransomware operation backed by an open-source project which sells affiliate access to an admin panel, a ransomware executable, and decryption tools, targeting 31 victims in 15 countries across sectors like business services and technology.
Who Alphalocker is
AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin panel, ransomware executable, and decryption key generator, lowering the barrier for entry-level cybercriminals using double-extortion tactics.
Recorded activity
Disclosures attributed to Alphalocker in this database run from January 2024 to February 2026, totalling 31 victims — 0.1% of everything tracked here. Alphalocker has listed victims in 15 countries in this database, most often United States, followed by United Kingdom and France. The sectors appearing most in its listings are Business Services, Technology, Manufacturing.
How Alphalocker is documented to operate
Exploit Public-Facing Application T1190 Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference →Phishing T1566 Initial Access
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.
Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit
MITRE ATT&CK reference →Data Encrypted for Impact T1486 Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Mitigations: Data Backup, Behavior Prevention on Endpoint
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Alphalocker across its recorded activity. They describe the group overall, not any single incident.
YARA detection rules
alphalocker.yar
/*
alphalocker ransomware
*/
rule alphalocker_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.alphalocker"
description = "Detects alphalocker ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "alphalocker" ascii nocase
$name2 = "ALPHALOCKER" ascii
$onion = "alphalocker.onion" ascii nocase
condition:
any of them
}
Community-contributed rules for Alphalocker, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Alphalocker is a ransomware threat group that has disclosed 31 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Alphalocker in our dataset dates to January 2024.
Geographically, Alphalocker has targeted organisations in 15 countries. The most frequently targeted nation is United States with 11 victim organisations. Other heavily targeted nations include United Kingdom, France, Brazil.
Industry-wise, Alphalocker shows a concentration in the Business Services, Technology, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Alphalocker likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 31 most recent of the 31 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 31 of 31)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | www.pyramisgroup.com www.pyramisgroup.com | 🇬🇷 Greece | Financial Services | Feb 28, 2026 |
| 2 | www.bew.co.th www.bew.co.th | 🇹🇭 Thailand | Technology | Nov 16, 2025 |
| 3 | www.automotiveml.com www.automotiveml.com | 🇺🇸 United States | Manufacturing | Nov 3, 2025 |
| 4 | www.myriversidedentaloffice.com www.myriversidedentaloffice.com | 🇺🇸 United States | Healthcare | Nov 3, 2025 |
| 5 | www.unterkofler.info www.unterkofler.info | 🇦🇹 Austria | — | Nov 3, 2025 |
| 6 | www.verdugohillsdental.com www.verdugohillsdental.com | 🇺🇸 United States | Healthcare | Oct 31, 2025 |
| 7 | www.mercantetubos.com.br www.mercantetubos.com.br | 🇧🇷 Brazil | Manufacturing | Oct 13, 2025 |
| 8 | www.libertydentaltown.com www.libertydentaltown.com | 🇺🇸 United States | Healthcare | Oct 5, 2025 |
| 9 | www.adhunikpower.com www.adhunikpower.com | 🇮🇳 India | Energy | Oct 1, 2025 |
| 10 | www.sonoshowmoveis.com.br www.sonoshowmoveis.com.br | 🇧🇷 Brazil | Consumer Services | Sep 29, 2025 |
| 11 | grupozeta.com & www.grupozetajalisco.com grupozeta.com | 🇲🇽 Mexico | Construction | Sep 16, 2025 |
| 12 | gazomet.pl & cgas.pl gazomet.pl | 🇵🇱 Poland | Energy | Sep 8, 2025 |
| 13 | ipathpr.com ipathpr.com | 🇺🇸 United States | Technology | Sep 8, 2025 |
| 14 | nubox.com & sumasaas.com nubox.com | 🇨🇱 Chile | Technology | Sep 8, 2025 |
| 15 | www.arkworkplacerisk.co.uk arkworkplacerisk.co.uk | 🇬🇧 United Kingdom | Business Services | Aug 9, 2024 |
| 16 | goftac.com/ firsttx.com First Texas Alliance Corp (FTAC) goftac.com | 🇺🇸 United States | Business Services | Aug 8, 2024 |
| 17 | biw-burger.de biw-burger.de | 🇩🇪 Germany | Manufacturing | Aug 6, 2024 |
| 18 | goftac.com/ firsttx.com First Texas Alliance Corp (FTAC) goftac.com | 🇺🇸 United States | Business Services | Aug 6, 2024 |
| 19 | www.carri.com carri.com | 🇫🇷 France | Technology | Aug 6, 2024 |
| 20 | www.consorzioinnova.it consorzioinnova.it | 🇮🇹 Italy | Technology | Aug 6, 2024 |
| 21 | https://goftac.com/ firsttx.com First Texas Alliance Corp (FTAC) goftac.com | 🇺🇸 United States | Business Services | Apr 24, 2024 |
| 22 | https://geodis.com geodis.com | 🇹🇭 Thailand | Transportation/Logistics | Apr 18, 2024 |
| 23 | https://www.consorzioinnova.it consorzioinnova.it | 🇮🇹 Italy | Business Services | Mar 9, 2024 |
| 24 | BM Catalysts bmcatalysts.co.uk bmcatalysts.co.uk | 🇬🇧 United Kingdom | Manufacturing | Feb 14, 2024 |
| 25 | elandenergy.com Eland Energy elandenergy.com | 🇺🇸 United States | Energy | Jan 26, 2024 |
| 26 | a24group.com ambition24hours.co.za a24group.com | 🇬🇧 United Kingdom | Healthcare | Jan 24, 2024 |
| 27 | accolade-group.com + levelwear.com +Taiwan microelectronics(CRM). levelwear.com | 🇹🇼 Taiwan | Consumer Services | Jan 24, 2024 |
| 28 | https://www.carri.com carri.com | 🇫🇷 France | Transportation/Logistics | Jan 24, 2024 |
| 29 | https://www.gadotbio.com/ Gadot Biochemical Industries Ltd gadotbio.com | IS | Manufacturing | Jan 24, 2024 |
| 30 | https://www.mikeferry.com mikeferry.com | 🇺🇸 United States | Business Services | Jan 24, 2024 |
| 31 | IntegrityInc.org Integrity Inc integrityinc.org | 🇺🇸 United States | Business Services | Jan 24, 2024 |
Frequently Asked Questions
What is Alphalocker ransomware?
Alphalocker is a ransomware threat group that has claimed 31 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Alphalocker attacked?
Alphalocker has claimed 31 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, France, Brazil.
Which countries does Alphalocker target?
Alphalocker has attacked organizations in 15 countries. The top targeted countries are: United States, United Kingdom, France, Brazil.
Which industries does Alphalocker target?
Alphalocker most frequently targets the Business Services, Technology, Manufacturing sectors based on victim disclosures in our database.
Is Alphalocker still active?
Alphalocker's most recent victim disclosure in our database was on February 28, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.