Site navigation

BlackLock Group Surges To Become Top Threat of 2025

Staff Writer

,

BlackLock
BlackLock’s unique malware and recruitment strategies have helped it become one of the most prolific ransomware groups, posing a major cybersecurity risk.

Security researchers have unmasked 2025’s fastest-growing ransomware gang, which in less than a year has emerged as a major player in the ransomware-as-a-service (RaaS) ecosystem.

First observed in March 2024, ReliaQuest found that the ‘BlackLock’ group became the 7th most prolific ransomware actor on data-leak sites by the end of last year, fueled by a staggering 1,425% increase in activity from Q3 2024.

According to the threat intelligence provider, BlackLock uses a double extortion tactic by encrypting data while stealing sensitive information, hoping to pressure victims with the threat of public exposure and the loss of data. 

Notably, the researchers found that the group uses custom malware in its attacks, built to target Windows, VMWare ESXi, and Linux environments, which ReliaQuest said is a hallmark of other top-tier groups like Play and Qilin.

This bespoke malware essentially renders security researchers blind, unable to find weaknesses or develop defences until the source code is leaked, unlike conventional ransomware builders, which though easier to use, have already leaked, allowing defenders to access and dissect the code.

The report notes that although at first glance BlackLock’s activities on ransomware forums are similar to other big players, its high volume of posts on leak sites last year is evidence of a superior effectiveness, leading ReliaQuest to predict that BlackLock will be the most active ransomware group of 2025.

According to the researchers, even the group’s data leak site shows evidence of BlackLock’s more sophisticated methods.

Distinct from other leak sites, BlackLock’s platform is reportedly packed with features designed to prevent targeted organisations from assessing the scope of breaches, including query detection and bogus file responses, piling pressure on firms to quickly pay ransoms before they can fully evaluate the impact of an attack.

ReliaQuest also found that unlike other RaaS operators, which routinely outsource early-stage tasks to affiliates, BlackLock actively recruits key players to support the early stages of ransomware attacks by driving malicious traffic to steer victims to harmful content, a tactic that likely helped fuel its aggressive rise over the latter part of 2024.

The group has also been witnessed building an extensive network of relationships on the Russian Anonymous Market Place (RAMP) forum where a BlackLock affiliate has nine times more posts than second place rival RansomHub.

This increased engagement has apparently allowed the group not only to quickly build its reputation, but given access to technical specialists to boost BlackLock’s operations.


Recommended reading


Worryingly, ReliaQuest said it found evidence suggesting that the group might now be turning its attention to exploiting Microsoft Entra Connect synchronization mechanics this year, with a blog post from a member of the group outlining how attackers could abuse the system and manipulate user attributes, as well as compromise on-premises environments.

“What makes BlackLock’s interest in Entra Connect stand out is its overt focus on initial access—a rarity among RaaS groups, which usually stick to post-compromise stages,” says the report.

“While attacks using Entra as a vector are unusual, the ransomware group “Storm-0501” demonstrated its potential by exploiting Entra using a different method in September 2024.

“Since BlackLock is likely to target Entra Tenant vulnerabilities in the future, it’s critical to secure this infrastructure now.” 

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data