Ransomware needs a way in. Stolen credentials are the cheapest one.
blacklocks Ransomware Group
Ransomware group profile
2Victims
RussiaSource country
18Impact score
Description
No description available for this group.
Threat Level & Status Breakdown
For blacklocks · Based on incidents in selected period
0.5threat level
Claimed100.0%2
First seenSep 2026
Last seenSep 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedSep 23, 2026
Recent activity
Monthly attack count for blacklocks in the selected period
2Total attacks
2peak in Sep
2avg / month
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for blacklocks
Defense Evasion
T1562
Impair Defenses
Execution
T1047
Windows Management Instrumentation
Impact
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
Lateral Movement
T1021
Remote Services
T1021.001
Remote Desktop Protocol
Other
T1045
T1045
T1565.001
T1565.001
T1071.001
T1071.001
T1483
T1483
T1363
T1363
Persistence
T1078
Valid Accounts
Victims(2)
Affected countries(5)
Countries where this group has been reported to target or leak victims.