| SYMBOL | COMMON_NAME | aka. SYNONYMS |
BlackLock is a ransomware group established around March 2024, operating under a RaaS model and actively recruiting affiliates. The ransomware is developed in Go, enabling cross-platform attacks on Windows, Linux, and VMware ESXi environments, and employs ChaCha20 for file encryption. BlackLock appends encryption keys and metadata to files for decryption post-ransom payment and utilizes a covert method to delete Volume Shadow Copy Service data to hinder recovery efforts. The group has been linked to operational failures due to significant OPSEC mistakes, including a breach of its leak site that exposed internal data.
There are currently no families associated with this actor.
| 2026-09-22
⋅
Cofense
⋅
From Payment Plan to Ransomware - Inside a Global Group Attack Global BlackLock |
| 2025-09-15
⋅
AhnLab
⋅
From El Dorado to BlackLock: Inside a Fast-Rising RaaS Threat BlackLock |
| 2025-07-14
⋅
Arda Büyükkaya
⋅
GLOBAL GROUP: Emerging Ransomware-as-a-Service, Supporting AI Driven Negotiation and Mobile Control Panel for Their Affiliates Global BlackLock |
| 2025-03-25
⋅
Resecurity
⋅
Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor's Infrastructure BlackLock |
| 2025-02-18
⋅
Reliaquest
⋅
Threat Spotlight: Inside the World’s Fastest Rising Ransomware Operator — BlackLock BlackLock |