Back to blog

Blog Post

BlackLock Ransomware Exposed and DragonForce Makes Moves

Share on social

Apr 4, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
BlackLock Ransomware Exposed and DragonForce Makes Moves

[BlackLock & DragonForce]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

Last week threat hunters successfully infiltrated the online infrastructure associated with BlackLock ransomware, uncovering crucial information about their modus operandi as a result.

According to Resecurity, identification of a vulnerability on the leak site of the group made it possible to extract configuration files, credentials, and a history of executed commands. This also resulted in clear web IP addresses being revealed, which were hidden behind Tor infrastructure.

BlackLock, which emerged in January 2025 and was previously known as El_Dorado, had listed 46 victims prior to the incident. Coincidently (or maybe using the same exploit) BlackLock’s leak site was also defaced by another ransomware operation known as DragonForce, who leaked chat logs that appear to show BlackLock's communications with its victims, among other files.

At the time of writing, DragonForce is making further waves in the cybercriminal community after alleging a merger with RansomHub, the most active ransomware group of 2024.

DragonForce made an announcement on the RAMP cybercrime forum stating that it had become partners with RansomHub and would merge their infrastructure. This announcement came after a brief period of uncertainty and speculation in the cybercriminal underground in regards to the reason that RansomHub’s data leak blog was inaccessible. At the time of writing, the blog is still offline.

It remains unclear whether this claim is correct or whether this is another hostile action of DragonForce against a fellow ransomware group. The announcement was met with various reactions from multiple threat actors, some expressing concern or asking why the administrator of RansomHub, known as "koley", failed to disclose anything about the situation.

If you’d like the latest dark web news and insights delivered into your inbox every Thursday at 10am, SIGN UP to the email version of Beacon.

BlackLock Ransomware Exposed and DragonForce Makes Moves
Charlotte Rhodes

Author

Charlotte Rhodes

Global VP Marketing at Searchlight Cyber

Charlotte Rhodes is Global VP of Marketing at Searchlight Cyber, where she leads the company's marketing strategy across brand, content, demand generation, and communications. She has been instrumental in building Searchlight's profile as the category leader in Preemptive Threat Exposure Management (PTEM).

Related Blog Posts

September 17, 2026

Beacon: AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers

September 16, 2026

How AI Is Collapsing Exploitation Timelines

September 15, 2026

Faster Leaked Credential Search with a rebuilt experience

September 10, 2026

Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient