Ransomware, Threat Intelligence

BlackLock ransomware on the rise, report finds

(Adobe Stock)

Despite only emerging last March, the BlackLock ransomware-as-a-service operation became the seventh most prolific ransomware gang last year after recording a 1,425% increase in activity between October and December, Cybernews reports.

Attacks conducted by BlackLock, which could be this year's most active ransomware group, involve the distribution of proprietary malware against Windows, VMware ESXi, and Linux systems for double extortion, an analysis from Reliaquest revealed. Immediate ransomware payments have been facilitated by BlackLock through its custom leak site, which impedes impacted organizations from conducting thorough breach evaluations. Additional findings showed BlackLock's usage of the Russian cybercrime forum RAMP for affiliate and traffer recruitment for early ransomware attack stages prior to major attack waves. "Recruitment posts for traffers explicitly outline requirements, signaling BlackLock's urgency to bring on candidates quickly — often prioritizing speed over operational security," said Reliaquest, which noted a significantly more cautious hiring process for higher-level and programmer positions within the RaaS operation.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds