Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Satanlockv2 ransomware

4 victims listed on the Satanlockv2 leak site across 3 countries. Most recent disclosure .

Victims
4
0% of all tracked
Countries
3
Most: Italy
Sectors
3
Most: Healthcare
First seen
Jul 2025
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Satanlockv2 and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Who Satanlockv2 is

SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after claiming attacks against roughly 67 organizations — though over 65% of listed victims were duplicates from other groups — leaking all stolen data publicly upon shutdown.

Recorded activity

Disclosures attributed to Satanlockv2 in this database run from July 2025 to July 2025, totalling 4 victims — 0% of everything tracked here. Satanlockv2 has listed victims in 3 countries in this database, most often Italy, followed by Thailand and Indonesia. The sectors appearing most in its listings are Healthcare, Education, Business Services.

YARA detection rules

satanlockv2.yar
/*
satanlockv2 ransomware
*/

rule satanlockv2_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.satanlockv2"
        description = "Detects satanlockv2 ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "satanlockv2" ascii nocase
        $name2 = "SATANLOCKV2" ascii
        $onion  = "satanlockv2.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Satanlockv2, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Satanlockv2 has disclosed 4 victims on its leak site, 0% of all ransomware listings tracked in this database. Its earliest disclosure here dates to July 2025.

The group has listed organisations in 3 countries, most often in Italy (1 victims), followed by Thailand, Indonesia.

By industry, its listings concentrate in Healthcare, Education, Business Services — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Satanlockv2 is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Satanlockv2 victims 4

Organization Disclosed
Satanlock project will be shut down
https://klinikdrindrajana.com/
IDIndonesia
fkk.ac.th
THThailand
studionotarile.com
ITItaly

Frequently asked questions

What is Satanlockv2 ransomware?

Satanlockv2 is a ransomware threat group that has claimed 4 victims since its first known activity in July 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Satanlockv2 attacked?

Satanlockv2 has claimed 4 victims in our database, representing 0% of all tracked ransomware attacks. The most targeted countries are Italy, Thailand, Indonesia.

Which countries does Satanlockv2 target?

Satanlockv2 has attacked organizations in 3 countries. The top targeted countries are: Italy, Thailand, Indonesia.

Which industries does Satanlockv2 target?

Satanlockv2 most frequently targets the Healthcare, Education, Business Services sectors based on victim disclosures in our database.

Is Satanlockv2 still active?

Satanlockv2's most recent victim disclosure in our database was on July 7, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.