SatanLock, also known as satanlockv2, was a ransomware group that emerged in early 2025 and ceased operations by July 2025. With a focus on data theft and extortion instead of traditional file encryption, the group claimed to have compromised 67 organizations and intended to publicly leak stolen data upon shutdown.
Key insights
•SatanLock primarily employed a double extortion model, threatening to leak stolen data if ransom demands were not met.
•The group rapidly compromised 67 organizations shortly after its inception, indicating a high level of operational efficiency.
•SatanLock potentially shared victim pools with other ransomware groups, suggesting connections to broader cybercriminal networks.
•Despite its short lifespan, the group made headlines due to its unique approach to handling ransom demands by announcing a data leak upon cessation.
•No specific malware or unique tools were attributed to SatanLock, indicating reliance on common ransomware tactics.