Skip to content
skopnix
← adversaries
Crime

BlackLocks

ransomware.liverefreshed 2026-09-15

sigil

Last 30 days

last seen 11 d ago

0
dispatches
1
victim
0
CVEs seen

seen against South Korea

sectors Manufacturing

Analyst brief

BlackLocks is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.

South Korea

assessed originobserved targets (1)

Observed targets

countries · 1

South Korea

sectors · 1

Manufacturing

as stated by MISP galaxy / ransomware.live — not inferred

Victims observed
1
First observed
Last observed on leak site
Velocity
1.0 victims / month
lifetime average, first to last observed

leak-site listings via ransomware.live — a quiet site is not a dead crew

Take it with you
References
Early access

Track BlackLocks on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected