blacklock logo

blacklock

2 incidentes 0 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Eldorado, El Dorado
Ver en IntelTracker → APTTrail →
BlackLock is a ransomware-as-a-service (RaaS) group that emerged in March 2024, initially operating under the name El Dorado before rebranding to BlackLock around September 2024. Assessed with high confidence to be of Russian origin, the group's primary motivation is financial gain through double extortion. What sets BlackLock apart is its custom-built ransomware written in Go, which enables cross-platform targeting of Windows, Linux, and VMware ESXi environments, distinguishing it from many groups that rely on leaked ransomware builders. The group actively recruits affiliates, developers, initial access brokers, and 'traffers' via Russian-speaking cybercrime forums like RAMP. Although it operated as BlackLock for a significant period, the actor behind it announced the launch of a new project, Mamona Ransomware, around March 2025, indicating a potential transition or rebranding.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaArubaBrazilCanadaCongo, the Democratic Republic of theCongoSpainFrance

Sectores atacados

Finance (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: blacklock (3 notes from ThreatLabz)18 Jun 2026
Report
blacklock - Ransom NotesEste grupo de ransomware tiene 3 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de res…