AiLock ransomware group
AiLock is a ransomware-as-a-service (RaaS) operation that first came to light in March 2025.
AiLock is a ransomware-as-a-service (RaaS) operation that first came to light in March 2025.
Threat actor not identified.
Storm’s operational methodology commonly involves acquiring infostealer-sourced credentials from underground marketplaces, validating them, and then using them for authentication before deploying ransomware.
Vexy is a newly observed ransomware and cyber extortion operation first publicly tracked in September 2026. Current public reporting remains limited, but available tracking identifies the group as active and indicates an extortion model centered on public victim listings and threats tied to data exposure.
The Aurora Ransomware Group is an active, Russian-speaking cybercrime operation that gained widespread attention in mid-2026 for pioneering the operational use of AI coding tools during live network intrusions.