Skip to content

BlackLock

BlackLock is a ransomware-as-a-service operation first observed in 2024 that initially operated as El Dorado or Eldorado before rebranding to BlackLock and later being linked to Mamona and GLOBAL GROUP branding.

Profile source: Mallory opens in a new tab

BlackLock

Family profile

BlackLock is a ransomware-as-a-service operation first observed in 2024 that initially operated as El Dorado or Eldorado before rebranding to BlackLock and later being linked to Mamona and GLOBAL GROUP branding. It is a cross-platform ransomware family written in Go and designed to target Windows, Linux, and VMware ESXi environments. Reporting consistently describes it as an affiliate-driven operation active across multiple sectors, including government, manufacturing, education, technology, healthcare-related organizations, and financial institutions, with victims concentrated in the United States and Europe.

BlackLock uses double extortion, combining file encryption with theft of victim data and threats to publish the stolen material. Its encryptors support broad local and network encryption behavior, including SMB share access, partial encryption options, multithreaded execution, and prioritization of selected data. Technical reporting describes use of ChaCha20 or XChaCha20 for file encryption with asymmetric protection of per-file key material, and post-encryption actions include dropping ransom notes and deleting recovery artifacts such as shadow copies and recycle-bin contents. ESXi-focused tradecraft has also been associated with the operation, including disruption of virtual machines and encryption of virtualization-related files, reflecting the broader ransomware trend toward hypervisor and recovery-denial targeting.

The operation has been heavily associated with Russian-speaking cybercrime ecosystems and with recruitment on the RAMP forum. Its operators have reportedly recruited affiliates, initial access brokers, developers, and traffers, indicating a modular intrusion model in which external actors help supply victim access. Observed or reported initial access mechanisms include social engineering via malicious shortcut files, phishing-style lures, and traffic-funneling arrangements, followed by loader execution, persistence establishment, and ransomware deployment. BlackLock has also shown interest in identity and hybrid-environment compromise, including abuse of Microsoft Entra Connect to reach on-premises environments.

BlackLock has been linked by multiple reports to code or operational overlap with DragonForce, including similar ransom notes and overlapping structures, although the two families are implemented in different languages. The group’s infrastructure and leak-site operations were reportedly compromised in 2025, and its leak site was later defaced amid apparent rivalry with DragonForce. Despite these disruptions, BlackLock has been regarded as a significant ransomware threat because of its rapid growth, aggressive affiliate recruitment, cross-platform capability, and focus on both encryption and data-theft extortion.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Persistence
  • Scanning

Operational record

1
Indicators
1
YARA rules
3
Ransom notes
1
Leak sites
0 available

Published indicators

Md5

1 total
  • f392807da3ee1f3e9702ce5fa91d418d

Reported operators

Threat actors

2 named in public reporting
DragonForce

analysis of the BlackLock ransomware ... revealed overlapping code structures with DragonForce ransomware, and the ransom notes were nearly identical.

$$$

Dubbed “BlackLock” (aka "El Dorado" or "Eldorado"), the ransomware-as-a-service (RaaS) outfit has existed since March 2024.

Exploited software

Vulnerabilities linked to BlackLock

2 CVEs

MITRE ATT&CK

BlackLock in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.