SYMBOLCOMMON_NAMEaka. SYNONYMS

BlackLock  (Back to overview)

aka: BlackLocks, El Dorado, Eldorado, GLOBAL GROUP, Mamona

BlackLock is a ransomware group established around March 2024, operating under a RaaS model and actively recruiting affiliates. The ransomware is developed in Go, enabling cross-platform attacks on Windows, Linux, and VMware ESXi environments, and employs ChaCha20 for file encryption. BlackLock appends encryption keys and metadata to files for decryption post-ransom payment and utilizes a covert method to delete Volume Shadow Copy Service data to hinder recovery efforts. The group has been linked to operational failures due to significant OPSEC mistakes, including a breach of its leak site that exposed internal data.


Associated Families

There are currently no families associated with this actor.


References
2026-09-22 ⋅ Cofense ⋅ Cofense Phishing Defense Center, Iris Suaner
From Payment Plan to Ransomware - Inside a Global Group Attack
Global BlackLock
2025-09-15 ⋅ AhnLab ⋅ ASEC
From El Dorado to BlackLock: Inside a Fast-Rising RaaS Threat
BlackLock
2025-07-14 ⋅ Arda Büyükkaya ⋅ EclecticIQ Threat Research Team
GLOBAL GROUP: Emerging Ransomware-as-a-Service, Supporting AI Driven Negotiation and Mobile Control Panel for Their Affiliates
Global BlackLock
2025-03-25 ⋅ Resecurity ⋅ Resecurity
Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor's Infrastructure
BlackLock
2025-02-18 ⋅ Reliaquest ⋅ ReliaQuest Threat Research
Threat Spotlight: Inside the World’s Fastest Rising Ransomware Operator — BlackLock
BlackLock

Credits: MISP Project