PlayBoy Locker is a ransomware-as-a-service (RaaS) operation that first emerged in September 2024, operating an 85/15 affiliate revenue split model. The group distinguished itself by offering a technically sophisticated platform with multi-operating system support, including Windows, Network Attached Storage (NAS), and VMware ESXi environments. Its active RaaS phase was relatively brief, as reports indicate the full source code was sold underground by late 2024 or November 2024, suggesting a potential cessation of its direct operations as a RaaS provider and broader proliferation of its malware. The primary motivation for PlayBoy Locker and its affiliates was financial gain through ransomware attacks and data extortion.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
ArgentinaAustraliaBelgiumCanadaSwitzerlandGermanySpainSaudi ArabiaUnited States
Sectores objetivo (SOCRadar)
Other Information ServicesMonetary Authorities-Central BankSoftware PublishersEnterprises & HoldingAccommodationConstructionPublic AdministrationRestaurantsInsuranceOther Personal Services