blacklock
2 incidentes
0 paises
1 sectores
ransomware RU Ultimo: 2026-06-25
Aliases: Eldorado, El Dorado
BlackLock is a ransomware-as-a-service (RaaS) group that emerged in March 2024, initially operating under the name El Dorado before rebranding to BlackLock around September 2024. Assessed with high confidence to be of Russian origin, the group's primary motivation is financial gain through double extortion. What sets BlackLock apart is its custom-built ransomware written in Go, which enables cross-platform targeting of Windows, Linux, and VMware ESXi environments, distinguishing it from many groups that rely on leaked ransomware builders. The group actively recruits affiliates, developers, initial access brokers, and 'traffers' via Russian-speaking cybercrime forums like RAMP. Although it operated as BlackLock for a significant period, the actor behind it announced the launch of a new project, Mamona Ransomware, around March 2025, indicating a potential transition or rebranding.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
Argentina
AustraliaAruba
Brazil
CanadaCongo, the Democratic Republic of theCongo
Spain
France
Sectores atacados
Finance (1)
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing
URLs nuevas detectadas en IntelTracker
Victimas (1)