Blacklock Ransomware Infrastructure Breached, Revealing Planned Attacks
ID: 39d7bdeb-73d5-55c5-a1fd-07108ffe91bf
STIX ID: report--39d7bdeb-73d5-55c5-a1fd-07108ffe91bf
Feed Name: GBHackers
Threat Score
Resecurity exploited an LFI vulnerability in Blacklock Ransomware's Tor-based data leak site during winter 2024–2025, accessing logs, MEGA-associated email accounts, and scheduled victim data publication plans up to 13 days before planned leaks; the firm alerted authorities, the DLS was defaced and configuration files disclosed, and analysis revealed code similarities to DragonForce suggesting possible links or consolidation among ransomware groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
