BlackLock is a ransomware-as-a-service operation that emerged in 2024 and is widely associated with the earlier El Dorado or Eldorado branding, later overlapping with Mamona and subsequently linked through operational continuity to GLOBAL GROUP. It is a cross-platform ransomware family written in Go and designed to target Windows and Linux systems, including virtualization environments such as VMware ESXi. Reporting consistently describes it as an affiliate-driven criminal service promoted on Russian-language underground forums by an operator using the alias "$$$", with recruitment extending beyond affiliates to traffers and initial access brokers.
BlackLock is characterized by double-extortion operations in which victim data is stolen prior to encryption and later used to pressure payment through leak-site publication threats. The malware supports broad encryption control through command-line options, can prioritize targets, partially encrypt files for speed, and has functionality for scanning and encrypting SMB-accessible network shares. Technical analyses describe its file-encryption workflow as using XChaCha20 or ChaCha20-family encryption with per-file key material and appended encrypted metadata to support attacker-side decryption. Post-encryption behavior includes dropping ransom notes and deleting recovery artifacts such as shadow copies and recycle-bin contents to inhibit restoration.
The family has been described as capable of targeting Windows, Linux, and ESXi environments, reflecting the broader ransomware trend toward hypervisor and recovery-denial attacks. Observed tradecraft and related reporting indicate interest in enterprise identity and virtualization infrastructure, including techniques relevant to Active Directory-connected ESXi administration. BlackLock has affected organizations across multiple sectors, including manufacturing, education, government, healthcare, technology, and financial services, with victims reported in North America, Europe, and parts of Asia.
BlackLock has also been notable for ecosystem relationships and rebranding activity. Multiple reports link it operationally to El Dorado, Mamona, and later GLOBAL GROUP through shared operators, forum personas, infrastructure patterns, and overlapping code or ransom-note characteristics. Separate reporting has identified similarities between BlackLock and DragonForce, including near-identical ransom-note structure and code overlap, while also documenting conflict between the groups, including the defacement of BlackLock leak infrastructure. Overall, BlackLock represents a professionalized RaaS threat focused on scalable affiliate operations, cross-platform encryption, data theft, and pressure tactics against enterprise victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The investigation centered on two specific file hashes that I’ve found with the associated command-and-control domains that together have strong attribution to the BlackLock ransomware-as-a-service (RaaS) operation, also known historically as Eldorado or El Dorado and later rebranded as GLOBAL GROUP.
The investigation centered on two specific file hashes that I’ve found with the associated command-and-control domains that together have strong attribution to the BlackLock ransomware-as-a-service (RaaS) operation, also known historically as Eldorado or El Dorado and later rebranded as GLOBAL GROUP.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
analysis of the BlackLock ransomware ... revealed overlapping code structures with DragonForce ransomware, and the ransom notes were nearly identical.
Dubbed “BlackLock” (aka "El Dorado" or "Eldorado"), the ransomware-as-a-service (RaaS) outfit has existed since March 2024.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newer ransomware strain in 2025 with cross-platform targeting including Windows, Linux, and VMware ESXi environments.
A ransomware-as-a-service operation using a custom Go-based builder to generate Windows, Linux, and ESXi encryptors. It is described as targeting virtualization infrastructure, especially ESXi, using recovery-denial tactics, encrypting datastores and virtual machine files, and dropping ransom notes such as HOW_RETURN_YOUR_DATA.TXT.
Ransomware variant observed targeting European financial institutions in 2025.
Referenced as a rival ransomware operation with a leak site targeted/defaced by DragonForce.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.