logo

Security shop pwns ransomware gang, passes insider info to authorities

ID: 80781ef8-dd3c-5fc4-9b97-05ee3e7c0ada

STIX ID: report--80781ef8-dd3c-5fc4-9b97-05ee3e7c0ada

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-03-27

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Resecurity discovered and exploited an LFI misconfiguration in the BlackLock ransomware gang’s TOR-based data leak site, recovering server configs, credentials and operator command histories. Using that access they cracked hashes, tracked operator activity, alerted CERT-FR and Canadian authorities to imminent leaks for several victims, and linked BlackLock to other ransomware brands (El Dorado, Mamona, DragonForce) while documenting TTPs such as use of Mega and rclone for exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.