BlackLock, also known as El Dorado or Eldorado, is a financially motivated ransomware-as-a-service operation first observed in March 2024. It targets organizations across multiple sectors and countries, including the United States, and conducts double extortion by stealing sensitive information, encrypting victim systems, and threatening public disclosure through a data-leak site. BlackLock develops custom ransomware for Windows, Linux, and VMware ESXi, with fewer features in its Linux variant than in its Windows counterpart. The operation recruits affiliates, developers, intrusion specialists, and malicious-traffic distributors through underground forums. Its representative, known as “$$$,” maintains an active presence on the Russian-language RAMP forum and engages with initial access brokers and other criminal operators. Associated intrusion techniques include ESXi account compromise, pass-the-hash lateral movement using stolen NTLM hashes, and deletion of Windows shadow copies to inhibit recovery. Its leak platform employs anti-automation controls that restrict rapid enumeration and bulk downloading of stolen material. BlackLock expanded substantially during late 2024, ranking seventh by ransomware data-leak-site activity in the fourth quarter. It subsequently listed more than 50 organizations on its leak site in May 2025. In March 2025, rival ransomware operation DragonForce compromised and defaced BlackLock’s leak infrastructure and exposed internal communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an affected ransomware group whose leak site was reportedly defaced in a background account of criminal rivalry. The passage's pronoun leaves the responsible actor unclear.
A rival criminal operation whose leak site was defaced by DragonForce.
A ransomware operation identified as a victim of DragonForce’s March 2025 leak-site defacements, mentioned as background to the ShinyHunters–Clop dispute.
Referenced as a ransomware group whose affiliates allegedly overlapped with Gentlemen operators.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.