Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors blacklock

Description

BlackLock is a rebranded version of another ransomware group known as Eldorado. It has since become one of the most active extortion syndicates in 2025, heavily targeting technology, manufacturing, construction, finance, and retail sectors. Known victims: 64 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

BlackLock is a rebranded ransomware group (formerly Eldorado) that emerged in 2023 and has become highly active by 2025, targeting sectors like technology, manufacturing, construction, finance, and retail. They primarily seek financial gain through extortion via ransomware deployments, showing moderate sophistication with a focus on organizational impact.

Goals & Targeting

BlackLock's strategic objectives revolve around generating immediate financial returns via ransomware deployments. Their targeting of technology, manufacturing, construction, finance, and retail sectors indicates a focus on industries that hold sensitive data, operate critical infrastructure, or have significant revenue dependencies on uninterrupted services. This approach allows the group to maximize the impact of their attacks while ensuring a higher probability of successful extortion.

Enhanced Description

BlackLock operates as a rebranded version of the Eldorado ransomware group, which has evolved into one of the most active extortion syndicates in 2025. The group primarily focuses on deploying ransomware to disrupt businesses and demand payment for decryption keys. Their targeting strategy centers on sectors where data loss or operational disruption would yield significant financial returns for victims. This approach positions BlackLock as a mid-tier threat actor with a clear emphasis on quick financial gains through organized extortion campaigns. While their specific tools and tactics remain less detailed in available intelligence, historical behavior suggests sophisticated yet modular methods aligned with typical ransomware operations.

Key Capabilities

  • Ransomware deployment
  • Extortion tactics
  • Phishing and/or exploit-kit usage for initial access
  • Lateral movement within networks
  • Data encryption for extortion

MITRE ATT&CK Tactics

Defense Evasion
Credential Access
Execution
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059
T1055
T1566.001
T1238
T1203

Software / Tooling

Cobalt Strike (possible)
Custom Ransomware Framework
Common Exploit Kits

Campaigns & Victims

BlackLock has demonstrated a consistent operational tempo since their emergence in late 2023, with campaigns targeting multiple sectors each month. Their victims include both large enterprises and中小型 businesses, suggesting an opportunistic approach to maximize ransom payments. The group's rebranding strategy indicates potential efforts to evade recognition or avoid direct association with historically tracked ransomware groups like Eldorado.

IOC Patterns

  • Spear-phishing campaigns with malicious attachments
  • Ransomware encryption of files across multiple systems
  • Presence of known ransomware-related tools and scripts in networks
  • Communication with compromised infrastructure via specific protocols
  • Anomalous network traffic related to command-and-control servers

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to monitor for signs of ransomware activity.
  • Enforce multi-factor authentication (MFA) policies to mitigate credential theft.
  • Conduct regular backups of critical systems and isolate backup data from network access to prevent encryption by ransomware.
  • Perform frequent employee training on recognizing phishing attempts and suspicious emails.

Suggested Tags

Ransomware
Financial Crime
Organizational Impact

Confidence Assessment

Confidence is high regarding BlackLock's association with ransomware activity, operational focus, and sector targeting. However, gaps exist in understanding their specific tools, tactics beyond general ransomware behavior, and exact geographic origins.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Crime
Organizational Impact

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 27, 2023
Last Seen
Jul 2, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.