ZeroHour

blacklocks

ransomware group · aka BlackLocks, BlackLock (similarly named 2025 operation; relationship unconfirmed), GOLD SALEM (Secureworks CTU designation for the 2025 BlackLock operation) · unknown · active since 2026-09-06 (earliest post on the leak site tracked by this dashboard); any earlier activity under the similar 'BlackLock' brand covered by vendors in 2025 is unconfirmed for this group

Victims · 7d
0▼1
Victims · 30d
1active targets
Victims · 90d
1
All-time (tracked)
1since 2026-09-06
Last post
09-06 23:43UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

BlackLocks is a ransomware and data-extortion brand tracked by this dashboard through its leak site, which has posted a single victim since first appearing on 2026-09-06, indicating very low observed volume. Public vendor reporting on this brand itself has not yet been identified; its name invites comparison with the BlackLock ransomware-as-a-service operation described in 2025 by Trend Micro, Cisco Talos, and Secureworks CTU (tracked as GOLD SALEM) as one of the fastest-rising extortion groups of early 2025, but any connection is unconfirmed. The 2025 BlackLock operation targeted Windows, VMware ESXi, and Linux systems across multiple regions before its Tor infrastructure was compromised and internal chats were leaked in March 2025 (BleepingComputer), after which the brand's public activity receded. With no vendor advisories, law-enforcement statements, or blockchain-analytics revenue estimates specific to BlackLocks available, its origin, affiliate structure, and ransom earnings are unknown, and defenders should rely on leak-site monitoring for emerging indicators.

Tactics & tooling
  • Runs a leak site that publishes stolen victim data and names victims (observed via dashboard tracking)
  • Data-theft extortion consistent with a double-extortion model; use of encryption and specific ransomware binaries not yet documented for this brand
  • RaaS/affiliate operation model (reported for the similarly named 2025 BlackLock operation)
  • Cross-platform targeting of Windows, VMware ESXi, and Linux hosts (reported for BlackLock in 2025 - Cisco Talos)
  • Possible shared code or lineage with the Eldorado ransomware family (2025 vendor research; unconfirmed for this brand)
  • No exploitation of specific CVEs has been publicly attributed to BlackLocks
Targeted sectors
unknown
Notable public victims

Gwangmyeong Industry Co., Ltd. (광명산업(주)) - South Korean company listed on the group's leak site on 2026-09-06; details beyond the listing not publicly confirmed

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
광명산업(주) · 9d agoURL: Kmin.co.kr Country: South Korea Description: Kwangmyung Industry is a manufacturing company established in 1985 that produces automotive parts, including automotive seats, molds, and jigs. Domestic operations consist of the headquarters, the Cheonan Central Research Institute, Asan, Gwangju, and Gyeongju factories, as well as the Export Division and Kwangmyung Engineering. Overseas subsidiaries include facilities in Ramos, Mexico, and Alabama, USA. DATA SIZE: 6TB

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .