Back to Threat Groups

a1project

Ransomware-as-a-Service

ransomware group

The locker is written in C/C++/ASM. <br/>It supports all systems starting from Windows 2003, has a separate binary for ESXi, and uses a unified encrypted file format across all systems. <br/>WINDOWS: <br/> • Two encryption modes: patch-based and file header. <br/> • Extensive configuration settings: from ignoring specific paths/extensions to terminating services/processes, unlocking occupied files, working with network shares, and more. <br/> • Arguments available for shutting down Hyper-V virtual machines, deleting backups, network scanning with logged-in user tokens. <br/> • Each build includes an obfuscated PowerShell script. <br/> • Execution is password-protected. <br/> • The locker itself is shellcode for x86/x64; if you have custom execution methods, we can provide the shellcode. <br/>ESXI: <br/> • Encrypts files in patches, with configurable path exclusions. <br/>The default configuration is pre-set to avoid disrupting Windows/ESXi/Linux systems. <br/> <br/>Our commission is 20% of payouts

Victims
0
records
First Discovered
victim
Last Discovered
Apr 13, 2026
victim
Inactive Since
Countries
0
hit

Group Activity

Last 12 months
Jun
2025
Jul
2025
Aug
2025
Sep
2025
Oct
2025
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026

Victims (0)

No victims recorded

Infrastructure

No sites tracked