Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Guardiola will receive another honor in Manchester. This is from that university

Republican proposal supported by Trump floats $1,000 baby bonds for families

Apple redesigns its operating system with “LiquidGlass” on WWDC 25

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Black Rock ransomware exposed after researchers exploited vulnerabilities at leaked sites
Identity

Black Rock ransomware exposed after researchers exploited vulnerabilities at leaked sites

userBy userMarch 29, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 29, 2025Ravi LakshmananCybercrime/Vulnerability

Black Rock Ransomware

In the Hacker Hacking instance, threat hunters managed to infiltrate online infrastructure related to a ransomware group called BlackRock, revealing important information about the techniques they take along the way.

Resecurity said it has identified a security vulnerability at the Data Leak Site (DLS) that the e-Crime group runs, which allows it to extract configuration files, credentials, and history of commands executed on the server.

The flaws are related to certain misconfigurations in BlackRock Ransomware data leak sites (DLS), leading to disclosure of ClearNet IP addresses related to the network infrastructure behind TOR Hidden Services (hosting) and additional service information.

Cybersecurity

It described the history of acquired commands as one of the biggest operational security (OPSEC) failures for BlackRock Ransomware.

BlackRock is a rebranded version of another ransomware group known as Eldorado. It has since become one of the most active terr syndicates in 2025, targeting the technology, manufacturing, construction, finance and retail sectors. As of last month, the site lists 46 casualties.

The affected organizations are in Argentina, Alba, Brazil, Canada, Congo, Croatia, Peru, France, Italy, the Netherlands, Spain, the United Arab Emirates, the UK and the United States.

Announced the launch of an underground affiliate network in mid-January 2025, the group has been observed to actively recruit traffic personnel to promote the early stages of the attack by directing victims to malicious pages that deploy malware that can establish initial access to the compromised system.

The vulnerability identified in the answer is a local file inclusion (LFI) bug that essentially causes web servers to leak sensitive information by performing a past traversal attack that contains a history of commands executed by operators at leak sites.

Some of the most notable findings are listed below –

Remove data to MEGA Cloud Storage Services using RCLONE. In some cases, you may even install a megaclient directly on the victim system. Threat actors have created at least eight accounts for MEGA using disposable email addresses used using YOPMAIL (e.g. Zubinnecrouzo-6860@yopmail.com “). Another ransomware stock codename Dragonforce is targeting Saudi Arabian organizations (Dragonforce is written in Visual C++, while BlackLock uses GO), and “$$$”, one of BlackRock’s leading operators, launched a short-lived ransomware project called Mamona on March 11th.

Cybersecurity

With an interesting twist, BlackLock’s DLS was tainted by Dragonforce on March 20th. Perhaps leveraging the same LFI vulnerability (or similar) will cause your configuration files and internal chat to your landing page. A day ago, the Mamona ransomware DLS was also tainted.

“It is unclear whether Black Rock Ransomware (as a group) has begun working with Dragon Force Ransomware or if it has quietly moved under new ownership,” the response said. “The new Masters could have taken over the project and its affiliate base to integrate the ransomware market, allowing them to understand their previous successors.”

“The key actor “$$$” shared no surprises after the incident with BlackRock and Mamona Ransomware. The actor was fully aware that his business could have already been compromised, so a silent “exit” from the previous project could be the most reasonable option. ”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleInterim President of Columbia University resigns and returns to his previous post
Next Article Myanmar – Thailand earthquake death rates pass 700 earthquake news
user
  • Website

Related Posts

More than 70 organizations in multiple sectors targeted by China-linked cyberspy groups

June 9, 2025

Two different botnets exploiting a vulnerability in Wazuh Server to launch a Mirai-based attack

June 9, 2025

Chrome 0-Day, Data Wipers, Misused Tools and Zero-Click iPhone Attacks

June 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Guardiola will receive another honor in Manchester. This is from that university

Republican proposal supported by Trump floats $1,000 baby bonds for families

Apple redesigns its operating system with “LiquidGlass” on WWDC 25

IONQ acquires nearly $1.1 billion in British quantum startup Oxford Ionics

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

IONQ acquires nearly $1.1 billion in British quantum startup Oxford Ionics

aixuspeed reports $500,000 in token commitments within the first 72 hours prior to sale

Vantage raises 720 million euros in the first ever euro ABS transaction backed by European data centres

Meta of lectures investing more than $100 billion in Silicon Valley’s top AI startups

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.