{
  "type": "bundle",
  "id": "bundle--8f5eff01-e714-5ccf-a7b1-103af3bb8f8c",
  "objects": [
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
      "created": "2017-01-20T00:00:00.000Z",
      "definition_type": "tlp",
      "name": "TLP:WHITE",
      "definition": {
        "tlp": "white"
      }
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-07T00:00:00.000Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "name": "skopnix",
      "identity_class": "organization",
      "description": "skopnix — open threat intelligence. Aggregated and published, not authored: cite the external_references, not us.",
      "contact_information": "https://skopnix.com"
    },
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-15T11:55:05.370Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "id": "intrusion-set--0283d8a5-efaf-5bc5-a8fa-71e5033a2dfa",
      "name": "BlackLocks",
      "aliases": [
        "BlackLocks"
      ],
      "description": "BlackLocks is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.",
      "first_seen": "2026-09-05T06:33:13.855Z",
      "last_seen": "2026-09-05T06:33:13.855Z",
      "external_references": [
        {
          "source_name": "skopnix",
          "external_id": "blacklocks",
          "url": "https://skopnix.com/actors/blacklocks"
        },
        {
          "source_name": "ransomware.live",
          "url": "https://www.ransomware.live/"
        }
      ]
    }
  ]
}