logo

Eldorado Ransomware Cruises Onto the Scene to Target VMware ESXi

ID: 63f48822-4d7a-5002-bfce-9130d713b605

STIX ID: report--63f48822-4d7a-5002-bfce-9130d713b605

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-07-09

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Eldorado is a Go-based RaaS observed since March that targets Windows and VMware ESXi (and offers a Linux build), marketed on cybercrime forums to recruit affiliates; it uses ChaCha20 and RSA-OAEP for encryption, can encrypt SMB shares and virtual machines, deletes shadow copies, leverages living-off-the-land tools (WMI/PowerShell), and is highly configurable to maximize impact across sectors such as education, real estate, and healthcare in the US.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.