AL

Alphalocker Ransomware

Tracked

Threat actor group tracked in the global ransomware database · Last disclosure: Feb 28, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
31
Total Victims
0.1% of all tracked
15
Countries Targeted
9
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Alphalocker and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Alphalocker is a ransomware operation backed by an open-source project which sells affiliate access to an admin panel, a ransomware executable, and decryption tools, targeting 31 victims in 15 countries across sectors like business services and technology.

Who Alphalocker is

AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin panel, ransomware executable, and decryption key generator, lowering the barrier for entry-level cybercriminals using double-extortion tactics.

Recorded activity

Disclosures attributed to Alphalocker in this database run from January 2024 to February 2026, totalling 31 victims — 0.1% of everything tracked here. Alphalocker has listed victims in 15 countries in this database, most often United States, followed by United Kingdom and France. The sectors appearing most in its listings are Business Services, Technology, Manufacturing.

How Alphalocker is documented to operate

Exploit Public-Facing Application T1190 Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.

Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing

MITRE ATT&CK reference →
Phishing T1566 Initial Access

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.

Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit

MITRE ATT&CK reference →
Data Encrypted for Impact T1486 Impact

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Mitigations: Data Backup, Behavior Prevention on Endpoint

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Alphalocker across its recorded activity. They describe the group overall, not any single incident.

YARA detection rules

alphalocker.yar
/*
alphalocker ransomware
*/

rule alphalocker_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.alphalocker"
        description = "Detects alphalocker ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "alphalocker" ascii nocase
        $name2 = "ALPHALOCKER" ascii
        $onion  = "alphalocker.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Alphalocker, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Alphalocker is a ransomware threat group that has disclosed 31 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Alphalocker in our dataset dates to January 2024.

Geographically, Alphalocker has targeted organisations in 15 countries. The most frequently targeted nation is United States with 11 victim organisations. Other heavily targeted nations include United Kingdom, France, Brazil.

Industry-wise, Alphalocker shows a concentration in the Business Services, Technology, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Alphalocker likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 31 most recent of the 31 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 31 of 31)

# Organization Country Sector Date
1 www.pyramisgroup.com www.pyramisgroup.com 🇬🇷 Greece Financial Services Feb 28, 2026
2 www.bew.co.th www.bew.co.th 🇹🇭 Thailand Technology Nov 16, 2025
3 www.automotiveml.com www.automotiveml.com 🇺🇸 United States Manufacturing Nov 3, 2025
4 www.myriversidedentaloffice.com www.myriversidedentaloffice.com 🇺🇸 United States Healthcare Nov 3, 2025
5 www.unterkofler.info www.unterkofler.info 🇦🇹 Austria Nov 3, 2025
6 www.verdugohillsdental.com www.verdugohillsdental.com 🇺🇸 United States Healthcare Oct 31, 2025
7 www.mercantetubos.com.br www.mercantetubos.com.br 🇧🇷 Brazil Manufacturing Oct 13, 2025
8 www.libertydentaltown.com www.libertydentaltown.com 🇺🇸 United States Healthcare Oct 5, 2025
9 www.adhunikpower.com www.adhunikpower.com 🇮🇳 India Energy Oct 1, 2025
10 www.sonoshowmoveis.com.br www.sonoshowmoveis.com.br 🇧🇷 Brazil Consumer Services Sep 29, 2025
11 grupozeta.com & www.grupozetajalisco.com grupozeta.com 🇲🇽 Mexico Construction Sep 16, 2025
12 gazomet.pl & cgas.pl gazomet.pl 🇵🇱 Poland Energy Sep 8, 2025
13 ipathpr.com ipathpr.com 🇺🇸 United States Technology Sep 8, 2025
14 nubox.com & sumasaas.com nubox.com 🇨🇱 Chile Technology Sep 8, 2025
15 www.arkworkplacerisk.co.uk arkworkplacerisk.co.uk 🇬🇧 United Kingdom Business Services Aug 9, 2024
16 goftac.com/ firsttx.com First Texas Alliance Corp (FTAC) goftac.com 🇺🇸 United States Business Services Aug 8, 2024
17 biw-burger.de biw-burger.de 🇩🇪 Germany Manufacturing Aug 6, 2024
18 goftac.com/ firsttx.com First Texas Alliance Corp (FTAC) goftac.com 🇺🇸 United States Business Services Aug 6, 2024
19 www.carri.com carri.com 🇫🇷 France Technology Aug 6, 2024
20 www.consorzioinnova.it consorzioinnova.it 🇮🇹 Italy Technology Aug 6, 2024
21 https://goftac.com/ firsttx.com First Texas Alliance Corp (FTAC) goftac.com 🇺🇸 United States Business Services Apr 24, 2024
22 https://geodis.com geodis.com 🇹🇭 Thailand Transportation/Logistics Apr 18, 2024
23 https://www.consorzioinnova.it consorzioinnova.it 🇮🇹 Italy Business Services Mar 9, 2024
24 BM Catalysts bmcatalysts.co.uk bmcatalysts.co.uk 🇬🇧 United Kingdom Manufacturing Feb 14, 2024
25 elandenergy.com Eland Energy elandenergy.com 🇺🇸 United States Energy Jan 26, 2024
26 a24group.com ambition24hours.co.za a24group.com 🇬🇧 United Kingdom Healthcare Jan 24, 2024
27 accolade-group.com + levelwear.com +Taiwan microelectronics(CRM). levelwear.com 🇹🇼 Taiwan Consumer Services Jan 24, 2024
28 https://www.carri.com carri.com 🇫🇷 France Transportation/Logistics Jan 24, 2024
29 https://www.gadotbio.com/ Gadot Biochemical Industries Ltd gadotbio.com IS Manufacturing Jan 24, 2024
30 https://www.mikeferry.com mikeferry.com 🇺🇸 United States Business Services Jan 24, 2024
31 IntegrityInc.org Integrity Inc integrityinc.org 🇺🇸 United States Business Services Jan 24, 2024

Frequently Asked Questions

What is Alphalocker ransomware?

Alphalocker is a ransomware threat group that has claimed 31 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Alphalocker attacked?

Alphalocker has claimed 31 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, France, Brazil.

Which countries does Alphalocker target?

Alphalocker has attacked organizations in 15 countries. The top targeted countries are: United States, United Kingdom, France, Brazil.

Which industries does Alphalocker target?

Alphalocker most frequently targets the Business Services, Technology, Manufacturing sectors based on victim disclosures in our database.

Is Alphalocker still active?

Alphalocker's most recent victim disclosure in our database was on February 28, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.