Threat Spotlight: Inside the Worldâs Fastest Rising Ransomware Operator â BlackLock
ID: 6df179f2-d675-5a8e-a8ae-98ca70c44c5e
STIX ID: report--6df179f2-d675-5a8e-a8ae-98ca70c44c5e
Feed Name: ReliaQuest Blog
ReliaQuest's report details the rapid rise of BlackLock (El Dorado), a sophisticated RaaS operator active since March 2024 that uses custom multi-platform ransomware and double extortion; it outlines the group's unusual, researcher-resistant data-leak site, extensive recruitment and operational activity on the RAMP forum, documented attack waves targeting Windows and VMware ESXi (with a Linux variant), and an emerging focus on abusing Microsoft Entra Connect—concluding with detection rules and mitigation guidance for affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
