Sovcali is a ransomware operation that emerged in August 2026, utilizing double-extortion tactics to coerce ransom payments from targeted organizations. The group gained notoriety for a significant exfiltration of proprietary automotive engineering data, threatening public disclosure to increase pressure on victims.
Key insights
•Operates using double-extortion tactics by exfiltrating sensitive data before encrypting systems.
•Targets high-value industries, particularly automotive and transportation sectors.
•Employs custom ransomware that utilizes AES-256 and RSA encryption for file locking.
•Accesses victim networks through bought compromised credentials or phishing attacks.
•Demonstrates high operational impact by staging and exfiltrating multi-terabyte databases.
•Listens for ransom payments through threats of public disclosure on a Tor leak site.