BlackLock, also known as El Dorado or Eldorado, is a ransomware-as-a-service operation first observed in March 2024 that rebranded to BlackLock in late 2024. Reporting links BlackLock closely to the Mamona ransomware family, with operational security overlaps indicating continuity between the brands. The actor has also been associated with the forum handle "$$$", which has been used to advertise BlackLock, El Dorado, and Mamona offerings and to recruit affiliates and other criminal service providers. BlackLock operates a double-extortion model, stealing victim data before encrypting systems and threatening public release to increase payment pressure. The group has actively recruited affiliates, traffers, and initial access brokers, indicating a scalable affiliate-driven intrusion model. BlackLock has advertised or deployed cross-platform ransomware for Windows, Linux, FreeBSD, and ESXi environments, and reporting indicates use of stolen-data staging and transfer workflows to support extortion operations. Victimology spans multiple countries and sectors, including government, defense, healthcare, technology, IT and managed service providers, academia, electronics, and religious organizations. Public reporting places confirmed victims in North America, Europe, Latin America, the Middle East, and Africa. The group’s affiliate rules reportedly prohibit targeting CIS countries and BRICS states, a pattern commonly associated with Russian-speaking cybercriminal ecosystems, but the available evidence does not support a high-confidence country attribution for BlackLock itself. BlackLock has shown signs of custom malware development rather than simple reuse of leaked builders. Separate reporting identified similarities between BlackLock and DragonForce ransom notes and operational artifacts, and BlackLock was later targeted by DragonForce in a criminal-on-criminal conflict that included leak-site defacement and exposure of internal materials. By mid-2025, BlackLock infrastructure and branding appeared to be disrupted, and later reporting tied the successor GLOBAL GROUP to BlackLock and Mamona through shared infrastructure, mutex reuse, and the same operator alias.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware group whose affiliates allegedly overlapped with Gentlemen operators.
Referenced as a ransomware operation for which The Gentlemen founder was previously an affiliate.
Referenced as a ransomware group whose former members were reportedly involved in Gentlemen's formation.
Referenced as a ransomware group from which former members joined the formation of Gentlemen.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.