New Eldorado ransomware targets Windows, VMware ESXi VMs
ID: fafc7c3f-0eab-5356-a16e-3d65863eb612
STIX ID: report--fafc7c3f-0eab-5356-a16e-3d65863eb612
Feed Name: Bleeping Computer
A new Go-based ransomware-as-a-service called Eldorado was observed in March, with locker variants for Windows and VMware ESXi and 16 claimed victims across U.S. real estate, education, healthcare, and manufacturing. Eldorado uses ChaCha20 for per-file encryption with RSA-OAEP-wrapped keys, encrypts SMB network shares, deletes Windows shadow copies, and offers affiliate customization (e.g., target directories, network subnets, self-deletion control), making it a high-impact, actively used ransomware operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
