BlackLock, previously operating under the alias Eldorado, has rapidly emerged as one of the most significant and active ransomware groups within the cybersecurity landscape. First observed in March 2024, BlackLock is primarily focused on a Ransomware-as-a-Service (RaaS) model, offering its custom-built ransomware to affiliates and other cybercriminals.
As of late 2024, BlackLock’s activity exploded by an alarming 1,425%, positioning it as one of the top ransomware operators globally. This explosive growth has placed it at the forefront of emerging cyber threats, with potential to become the most prolific ransomware group in 2025.Initial Access
2. Exploitation and Lateral Movement
3. Encryption of Data
4. Collaboration with Other Threat Actors
5. Hacktivism
6. Leak Site Design
BlackLock’s leak site is sophisticated and designed to frustrate investigators. It includes features such as:
7. Emerging Trends
Recommendations:
SOURCES:
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.
Keeping this cookie enabled helps us to improve our website.
Please enable Strictly Necessary Cookies first so that we can save your preferences!
This website uses the following additional cookies:
(List the cookies that you are using on the website here.)
More information about our Cookie Policy