Security researchers at Resecurity have successfully infiltrated the digital infrastructure of BlackLock ransomware group by exploiting a vulnerability in their data leak site (DLS). This security breach allowed researchers to extract configuration files, credentials, and command history—revealing what experts call one of the group’s biggest operational security failures.
## The Vulnerability and Findings
The security flaw involved a misconfiguration in BlackLock’s DLS that exposed clearnet IP addresses behind their TOR hidden services. Specifically, researchers exploited a local file inclusion (LFI) vulnerability that enabled path traversal attacks, giving them access to sensitive server information.
Key discoveries from the breach include:
– BlackLock operators use Rclone to exfiltrate victim data to MEGA cloud storage
– At least eight MEGA accounts were created using disposable YOPmail addresses
– Source code analysis revealed similarities with DragonForce ransomware, though BlackLock is written in Go while DragonForce uses Visual C++
– A main operator identified as “$$$” launched a short-lived ransomware project called Mamona in March 2025
## BlackLock’s Operations and Targets
BlackLock, a rebranded version of the Eldorado ransomware group, has become one of the most active extortion syndicates in 2025. The group primarily targets organizations in technology, manufacturing, construction, finance, and retail sectors across 14 countries including the United States, United Kingdom, France, and Brazil.
Since launching its underground affiliate network in January 2025, BlackLock has listed 46 victims on its site and actively recruits “traffers” to facilitate initial access to target systems.
## Unexpected Developments
In a surprising turn of events, BlackLock’s DLS was defaced by DragonForce on March 20, likely exploiting the same vulnerability discovered by Resecurity. The day before, Mamona’s DLS suffered a similar fate.
Resecurity analysts suggest this could indicate either cooperation between the groups or a silent takeover of BlackLock’s operations. The main actor “$$$” showed no surprise following these incidents, suggesting possible awareness of the compromised operation and a strategic exit from the project.
