BrLock, also referred to as BlackLock or formerly El Dorado, is a ransomware-as-a-service (RaaS) operation that emerged in March 2024. The group uses custom-built ransomware written in Go, targeting multiple platforms with a focus on double extortion tactics to pressure victims into paying ransoms.
Key insights
•Utilizes custom Go-based ransomware designed for cross-platform compatibility.
•Employs double extortion by encrypting data and exfiltrating sensitive information.
•Gains initial access through 'traffers' who exploit vulnerabilities like Microsoft Entra Connect.
•Deletes Volume Shadow Copies to inhibit recovery options for victims.
•Targets a wide range of sectors, including finance, healthcare, and manufacturing.
•Implements sophisticated obfuscation techniques to evade detection.
•Maintains a unique data leak site to enhance pressure on victims.