logo

Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor’s Infrastructure

ID: 5ad1f899-6102-57bb-806c-cf39dd01a185

STIX ID: report--5ad1f899-6102-57bb-806c-cf39dd01a185

Feed Name: DataBreaches.Net

Threat Score
70/100

Date Published: 2025-03-27

Date Updated: 2026-05-11

Author: Dissent

...
...

Resecurity's HUNTER team discovered and exploited a vulnerability in the BlackLock (aka El Dorado/Eldorado) ransomware group's Tor-hosted data leak site, allowing collection of logs, hosting/ISP details, login timestamps and associated MEGA accounts used to store stolen data; this covert intelligence enabled prediction and prevention of some planned attacks and protection of undisclosed victims. The report emphasizes proactive offensive cyber operations combined with threat intelligence as an effective method to disrupt RaaS activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.