Eldorado Ransomware Cruises Onto the Scene to Target VMware ESXi
ID: 63f48822-4d7a-5002-bfce-9130d713b605
STIX ID: report--63f48822-4d7a-5002-bfce-9130d713b605
Feed Name: Dark Reading
Threat Score
Eldorado is a Go-based RaaS observed since March that targets Windows and VMware ESXi (and offers a Linux build), marketed on cybercrime forums to recruit affiliates; it uses ChaCha20 and RSA-OAEP for encryption, can encrypt SMB shares and virtual machines, deletes shadow copies, leverages living-off-the-land tools (WMI/PowerShell), and is highly configurable to maximize impact across sectors such as education, real estate, and healthcare in the US.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
