Skip to content

BlackLock

BlackLock is a Go-based ransomware family operated through a ransomware-as-a-service (RaaS) affiliate program.

BlackLock

Family profile

BlackLock is a Go-based ransomware family operated through a ransomware-as-a-service (RaaS) affiliate program. First observed in March 2024 under the name El Dorado, also spelled Eldorado, the operation adopted the BlackLock name in late 2024. It targets Windows, Linux, and VMware ESXi environments and uses double extortion, combining file encryption with data theft and threats to publish stolen information on a Tor-hosted leak site.

The ransomware supports configurable encryption scope, delayed execution, multithreading, partial encryption, and prioritization of selected directories. Windows variants can scan and access SMB shares using the open-source go-smb2 library, enabling encryption of accessible network files. Analyzed implementations use XChaCha20 with randomly generated per-file keys and nonces. Encryption metadata is appended to affected files and protected using an ECDH-derived shared key and authenticated encryption. BlackLock changes file extensions and places ransom notes in affected directories. Windows variants delete Volume Shadow Copies and Recycle Bin contents to impede recovery; an analyzed implementation performs shadow-copy deletion through in-memory shellcode and COM/WMI rather than conventional command-line execution.

The operation recruits affiliates, developers, initial access brokers, and traffic-distribution specialists through Russian-language criminal forums, including RAMP. An administrator using the alias “$$$” has been associated with BlackLock, El Dorado, Mamona, and GLOBAL GROUP. Stolen-data workflows have used rclone and MEGA for transfer and storage. Victims span multiple countries and industries, including government, education, manufacturing, technology, healthcare-related organizations, and European financial institutions. BlackLock’s leak-site infrastructure was compromised and defaced in March 2025, exposing internal operational information.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Scanning

Samples

Recent samples

2 sandbox samples in the Derp library, newest 2 shown

Reported operators

Threat actors

2 named in public reporting
DragonForce

analysis of the BlackLock ransomware ... revealed overlapping code structures with DragonForce ransomware, and the ransom notes were nearly identical.

$$$

Dubbed “BlackLock” (aka "El Dorado" or "Eldorado"), the ransomware-as-a-service (RaaS) outfit has existed since March 2024.

Exploited software

Vulnerabilities linked to BlackLock

2 CVEs

MITRE ATT&CK

BlackLock in ATT&CK

1 distinct techniques