Md5
1 totalf392807da3ee1f3e9702ce5fa91d418d
BlackLock is a ransomware-as-a-service operation that emerged in 2024 and is widely associated with the earlier El Dorado or Eldorado branding, later overlapping with Mamona and subsequently linked through operational continuity to GLOBAL GROUP.
Profile source: Mallory opens in a new tabBlackLock
BlackLock is a ransomware-as-a-service operation that emerged in 2024 and is widely associated with the earlier El Dorado or Eldorado branding, later overlapping with Mamona and subsequently linked through operational continuity to GLOBAL GROUP. It is a cross-platform ransomware family written in Go and designed to target Windows and Linux systems, including virtualization environments such as VMware ESXi. Reporting consistently describes it as an affiliate-driven criminal service promoted on Russian-language underground forums by an operator using the alias "$$$", with recruitment extending beyond affiliates to traffers and initial access brokers.
BlackLock is characterized by double-extortion operations in which victim data is stolen prior to encryption and later used to pressure payment through leak-site publication threats. The malware supports broad encryption control through command-line options, can prioritize targets, partially encrypt files for speed, and has functionality for scanning and encrypting SMB-accessible network shares. Technical analyses describe its file-encryption workflow as using XChaCha20 or ChaCha20-family encryption with per-file key material and appended encrypted metadata to support attacker-side decryption. Post-encryption behavior includes dropping ransom notes and deleting recovery artifacts such as shadow copies and recycle-bin contents to inhibit restoration.
The family has been described as capable of targeting Windows, Linux, and ESXi environments, reflecting the broader ransomware trend toward hypervisor and recovery-denial attacks. Observed tradecraft and related reporting indicate interest in enterprise identity and virtualization infrastructure, including techniques relevant to Active Directory-connected ESXi administration. BlackLock has affected organizations across multiple sectors, including manufacturing, education, government, healthcare, technology, and financial services, with victims reported in North America, Europe, and parts of Asia.
BlackLock has also been notable for ecosystem relationships and rebranding activity. Multiple reports link it operationally to El Dorado, Mamona, and later GLOBAL GROUP through shared operators, forum personas, infrastructure patterns, and overlapping code or ransom-note characteristics. Separate reporting has identified similarities between BlackLock and DragonForce, including near-identical ransom-note structure and code overlap, while also documenting conflict between the groups, including the defacement of BlackLock leak infrastructure. Overall, BlackLock represents a professionalized RaaS threat focused on scalable affiliate operations, cross-platform encryption, data theft, and pressure tactics against enterprise victims.
f392807da3ee1f3e9702ce5fa91d418dReported operators
analysis of the BlackLock ransomware ... revealed overlapping code structures with DragonForce ransomware, and the ransom notes were nearly identical.
Dubbed “BlackLock” (aka "El Dorado" or "Eldorado"), the ransomware-as-a-service (RaaS) outfit has existed since March 2024.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.