logo

Blacklock Ransomware Infrastructure Breached, Revealing Planned Attacks

ID: 39d7bdeb-73d5-55c5-a1fd-07108ffe91bf

STIX ID: report--39d7bdeb-73d5-55c5-a1fd-07108ffe91bf

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2025-03-27

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Resecurity exploited an LFI vulnerability in Blacklock Ransomware's Tor-based data leak site during winter 2024–2025, accessing logs, MEGA-associated email accounts, and scheduled victim data publication plans up to 13 days before planned leaks; the firm alerted authorities, the DLS was defaced and configuration files disclosed, and analysis revealed code similarities to DragonForce suggesting possible links or consolidation among ransomware groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.