BlackLock is a Go-based ransomware family and ransomware-as-a-service operation first observed in March 2024 under the name El Dorado, also spelled Eldorado. The operation adopted the BlackLock name in late 2024. It uses double extortion, combining file encryption with theft of sensitive information and threats to publish stolen data. Its ransomware targets Windows, Linux, and VMware ESXi environments. Victims span multiple countries and sectors, including manufacturing, education, government, technology, and financial services, with substantial activity against US organizations.
BlackLock supports configurable encryption scope, delayed execution, multithreading, folder prioritization, and partial encryption. Its Windows implementation can scan and access SMB shares using the go-smb2 library, allowing encryption of network-accessible data. Analyzed samples use XChaCha20 with randomly generated per-file keys and nonces. Encryption metadata is protected using an ECDH-derived shared key and appended to encrypted files. The malware renames encrypted files and deposits ransom notes. It inhibits recovery by deleting Windows Volume Shadow Copies and clearing Recycle Bin contents; analyzed Windows samples perform shadow-copy deletion through COM/WMI using in-memory shellcode. Associated intrusions also use stolen NTLM hashes for pass-the-hash lateral movement. The operation has used MEGA and rclone for stolen-data transfer and storage.
The Russian-speaking operator known as “$$$” recruits affiliates, developers, traffic distributors, and initial access brokers through the RAMP cybercrime forum. This outsourced access model supports deployment across diverse victim networks rather than a single established infection vector. The same operator has been associated with the Mamona and GLOBAL ransomware operations. BlackLock maintains a Tor-based data-leak site with anti-automation restrictions that obstruct bulk retrieval of leaked information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The investigation centered on two specific file hashes that I’ve found with the associated command-and-control domains that together have strong attribution to the BlackLock ransomware-as-a-service (RaaS) operation, also known historically as Eldorado or El Dorado and later rebranded as GLOBAL GROUP.
The investigation centered on two specific file hashes that I’ve found with the associated command-and-control domains that together have strong attribution to the BlackLock ransomware-as-a-service (RaaS) operation, also known historically as Eldorado or El Dorado and later rebranded as GLOBAL GROUP.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
First observed in March 2024, “BlackLock” (aka El Dorado or Eldorado) has rapidly emerged as a major player in the ransomware-as-a-service (RaaS) ecosystem.
analysis of the BlackLock ransomware ... revealed overlapping code structures with DragonForce ransomware, and the ransom notes were nearly identical.
Dubbed “BlackLock” (aka "El Dorado" or "Eldorado"), the ransomware-as-a-service (RaaS) outfit has existed since March 2024.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in background reporting about apparent defacement of ransomware leak sites. No malware behavior is described.
A newer ransomware strain in 2025 with cross-platform targeting including Windows, Linux, and VMware ESXi environments.
A ransomware-as-a-service operation using a custom Go-based builder to generate Windows, Linux, and ESXi encryptors. It is described as targeting virtualization infrastructure, especially ESXi, using recovery-denial tactics, encrypting datastores and virtual machine files, and dropping ransom notes such as HOW_RETURN_YOUR_DATA.TXT.
Ransomware variant observed targeting European financial institutions in 2025.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.