BlackLock
MISP
Tipo:
Unknown
Unknown
Paese:
Unknown
Unknown
Prima attivita:
Unknown
Unknown
Dettagli:
BlackLock is a ransomware group established around March 2024, operating under a RaaS model and actively recruiting affiliates. The ransomware is developed in Go, enabling cross-platform attacks on Windows, Linux, and VMware ESXi environments, and employs ChaCha20 for file encryption. BlackLock appends encryption keys and metadata to files for decryption post-ransom payment and utilizes a covert method to delete Volume Shadow Copy Service data to hinder recovery efforts. The group has been linked to operational failures due to significant OPSEC mistakes, including a breach of its leak site that exposed internal data.
Riferimenti (6)
- asec.ahnlab.com - 90175
- reliaquest.com - Threat Spotlight Inside The Worlds Fastest Rising Ransomware Operator Blacklock
- resecurity.com - Blacklock Ransomware A Late Holiday Gift With Intrusion Into The Threat Actors Infrastructure
- cofense.com - From Payment Plan To Ransomware Inside A Global Group Attack
- exchange.xforce.ibmcloud.com - Guid:5689a0200c31471e9cf96949cd00c12c
- blog.eclecticiq.com - Global Group Emerging Ransomware As A Service
Alias (10)
El Dorado
BlackLocks
Eldorado
Mamona
GLOBAL GROUP
El Dorado
BlackLocks
Eldorado
Mamona
GLOBAL GROUP
Metadata
| ID: | 1133 |
| Created: | 06/10/2026 04:00 |
| Updated: | 06/10/2026 16:00 |