BlackLock is a rebranded version of another ransomware group known as Eldorado. It has since become one of the most active extortion syndicates in 2025, heavily targeting technology, manufacturing, construction, finance, and retail sectors. Known victims: 64 3 ransom note(s) on file
Objectives
Executive Summary
BlackLock is a rebranded ransomware group (formerly Eldorado) that emerged in 2023 and has become highly active by 2025, targeting sectors like technology, manufacturing, construction, finance, and retail. They primarily seek financial gain through extortion via ransomware deployments, showing moderate sophistication with a focus on organizational impact.
Goals & Targeting
BlackLock's strategic objectives revolve around generating immediate financial returns via ransomware deployments. Their targeting of technology, manufacturing, construction, finance, and retail sectors indicates a focus on industries that hold sensitive data, operate critical infrastructure, or have significant revenue dependencies on uninterrupted services. This approach allows the group to maximize the impact of their attacks while ensuring a higher probability of successful extortion.
Enhanced Description
BlackLock operates as a rebranded version of the Eldorado ransomware group, which has evolved into one of the most active extortion syndicates in 2025. The group primarily focuses on deploying ransomware to disrupt businesses and demand payment for decryption keys. Their targeting strategy centers on sectors where data loss or operational disruption would yield significant financial returns for victims. This approach positions BlackLock as a mid-tier threat actor with a clear emphasis on quick financial gains through organized extortion campaigns. While their specific tools and tactics remain less detailed in available intelligence, historical behavior suggests sophisticated yet modular methods aligned with typical ransomware operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BlackLock has demonstrated a consistent operational tempo since their emergence in late 2023, with campaigns targeting multiple sectors each month. Their victims include both large enterprises and中小型 businesses, suggesting an opportunistic approach to maximize ransom payments. The group's rebranding strategy indicates potential efforts to evade recognition or avoid direct association with historically tracked ransomware groups like Eldorado.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is high regarding BlackLock's association with ransomware activity, operational focus, and sector targeting. However, gaps exist in understanding their specific tools, tactics beyond general ransomware behavior, and exact geographic origins.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics