Slug is an obscure ransomware group that first emerged in January 2024, appearing to operate with financial motivations typical of most ransomware actors. Based on limited public reporting, the group has maintained a very low profile with minimal documented activity since its emergence. The group's origin and potential affiliations remain unknown due to the limited scope of their operations, and there is insufficient public information to determine whether they operate as part of a ransomware-as-a-service model or as an independent entity. Attack methodology details have not been publicly documented by major security firms or government agencies, reflecting the group's minimal operational footprint and limited impact on the broader threat landscape. The group's most notable characteristic is their apparent focus on Ireland's transportation and logistics sector, though with only one documented victim, this targeting pattern may not represent a deliberate specialization. Based on available intelligence from established security researchers, Slug remains a marginal player in the ransomware ecosystem with unclear current operational status. The group has been linked to 1 public disclosures across our corpus. First observed on a leak site on January 18, 2024. The operation is currently inactive.
Sector and geography
This disclosure adds to ransomware activity in the Transportation/Logistics sector, which has 847 disclosures indexed across all operators we track. Geographically, aercap.com is reported in Ireland, a country with 7 ransomware disclosures in our corpus.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.