A new, sophisticated ransomware operation, dubbed BlackLock ransomware, has emerged as a significant threat to organizations worldwide, demonstrating advanced capabilities cross-platform and targeting various computing environments.

It initially operated under the name 'El Dorado', but was renamed BlackLock in September 2024. The group established itself as a powerful player in the ransomware landscape, with victims spanning multiple countries and industries.
The technical sophistication of BlackLock lies in its development using the Go. This allows the malware to run seamlessly on Windows, Linux, and VMware ESXi. This cross-platform approach significantly expands the attack surface, allowing malicious actors to compromise entire IT infrastructures simultaneously.
See also: MalTerminal AI malware: Abuse of OpenAI's GPT-4
The ransomware operates under the Ransomware-as-a-Service (RaaS) model, actively recruiting capable collaborators through Russian-language cybercrime forums, particularly RAMP.
BlackLock ransomware: Advanced encryption
ASEC reports indicate that the ransomware implements strong cryptographic techniques , using Go's crypto package to encrypt files via ChaCha20.NewUnauthenticatedCipher() with randomly generated 32-byte FileKeys and 24-byte nonces for each targeted file. This approach ensures that each encrypted file receives a unique encryption key , making recovery virtually impossible without the attackers' decryption tools.
The sophisticated key management system of BlackLock ransomware uses Elliptic Curve Diffie-Hellman (ECDH) key exchange to generate shared keys for metadata encryption. The ransomware adds encrypted metadata (containing the FileKey) and victim information to each file. This double encryption strategy prevents victims from independently recovering their data, while ensuring that attackers can decrypt files after paying the ransom.

The malware supports extensive command-line arguments for operational flexibility, including -path for targeted encryption, -delay for timed execution, -threads for performance optimization, and -perc for partial file encryption to speed up the attack process.
See also: Hackers distribute BeaverTail in crypto scams
Additionally, BlackLock ransomware includes provisions for VMware ESXi via the -esxi, although this feature appears not to have been used in the analyzed samples.
BlackLock demonstrates advanced network propagation by using open-source projects such as go-smb2 to scan and access SMB shared folders on Windows networks.
The ransomware can be 'authenticated' using simple passwords or NTLM hashes specified via the -u, -p and -h parameters, allowing lateral movement across corporate networks and simultaneous encryption of network storage systems .
To eliminate recovery options, BlackLock uses sophisticated techniques data destruction that target the Volume Shadow Copy Service (VSS) and the contents of the Recycle Bin.
Also, instead of executing obvious command-line instructions, the malware constructs COM object instances to execute WMI queries via shellcode, which is loaded directly into memory. As a result, detection becomes significantly more difficult for security solutions.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: SystemBC botnet targets VPS servers
The ransomware creates ransom notes titled HOW_RETURN_YOUR_DATA.TXT in each encrypted directory, containing threatening language warning victims of business disruption and data leakage if the ransom demands. This psychological pressure tactic, combined with the technical impossibility of independent data recovery, creates significant pressure on victims. Organizations must implement comprehensive security strategies to protect themselves from this new threat.

Ransomware protection
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using email security solutions for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
