iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In March 2025, cybersecurity company Resecurity said it exploited a vulnerability in BlackLock ransomware’s Tor-based data leak site, obtaining server-side information that it used to alert some victims about planned data releases. The account describes a targeted intrusion and reported intelligence value—not proof that every victim was identified or that BlackLock was permanently taken down.
What Resecurity says happened
In a report published March 25, 2025, Resecurity said it found a misconfiguration in BlackLock’s Tor-based data leak site (DLS) that disclosed clearnet IP addresses associated with the site’s hosting infrastructure. The company then exploited a Local File Include (LFI) vulnerability to collect information stored on the server.
An LFI flaw can allow an attacker to make an application include or expose files from its own server. In this case, Resecurity says the flaw gave its researchers access to server-side material, including configuration files and credentials. This is Resecurity’s account of its own activity; the reviewed reporting does not independently verify each technical step.
Free tools Windows power users keep installed
One-click scans. No signup required.
What information the researchers say they obtained
Resecurity said the collected material provided a view of BlackLock’s infrastructure and operations, including:
#1 Best Overall
- Network and hosting details, including clearnet IP addresses associated with the hosting infrastructure.
- Configuration files and credentials.
- Login timestamps.
- Accounts on file-sharing services used to store stolen victim data.
- A chronology of when victim data was published or was expected to be published.
IT Pro reported that Resecurity researchers described the exposed command history as “one of the biggest OPSEC failures of Blacklock Ransomware.” That characterization is the researchers’ assessment, quoted by IT Pro.
How the information was used to warn victims
Resecurity said the operational details helped it anticipate some planned attacks and alert victims whose data had not yet been publicly released. The company reported contacting the Canadian Centre for Cyber Security about a planned release affecting a Canada-based victim 13 days before BlackLock published the data. IT Pro also reported that Resecurity alerted a victim in France.
Those are outcomes reported by Resecurity and IT Pro. The reviewed accounts do not independently quantify how many attacks were prevented, how many victims received warnings, or how many disclosures were stopped. A warning about an impending publication can give an organization time to prepare, but it does not by itself establish that an intrusion was prevented or stolen data recovered.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
How many BlackLock victims were identified?
Resecurity said it had identified 46 victims as of February 10, 2025. Its report listed affected organizations in electronics, academia, religious organizations, defense, healthcare, technology, IT and managed-service providers, and government. The listed locations were Argentina, Aruba, Brazil, Canada, Congo, Croatia, Peru, France, Italy, Spain, the Netherlands, the United States, the United Kingdom, and the UAE.
Rank #3
Resecurity cautioned that 46 might not be the full count: some organizations could remain undisclosed during extortion, while others could be named later. Treat the number as the company’s dated count, not a definitive total of BlackLock victims.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.BlackLock’s reported links and the DragonForce question
Resecurity described BlackLock as also known as El Dorado or Eldorado, and said the actor using the alias “$$$” had links to El Dorado and Mamona. The company pointed to near-identical victim lists on the El Dorado and BlackLock leak sites as evidence of a strong connection. This is Resecurity’s attribution, not an independently adjudicated identification of the people or group behind the aliases.
Rank #4
In a March 28, 2025 report, IT Pro said DragonForce appeared to have hijacked or defaced BlackLock’s dark web site. The reporting relayed Resecurity’s speculation about whether the event indicated cooperation, a takeover, or a false flag; it did not settle which explanation was correct. The reported site incident is not evidence that BlackLock permanently ceased operating.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteQuick Recap
Best Value
What the report does—and does not—establish
- What Resecurity reported: its researchers accessed BlackLock’s Tor leak site by exploiting an LFI vulnerability after identifying a configuration issue, and collected operational information.
- Reported impact: Resecurity said it used the information to warn some victims about planned releases; its victim count was 46 as of February 10, 2025, with a warning that the count could be incomplete.
- What remains unresolved: the number of attacks actually prevented, BlackLock’s complete victim count, the meaning of the DragonForce site incident, and whether BlackLock permanently stopped operating.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

