logo

New Eldorado ransomware targets Windows, VMware ESXi VMs

ID: fafc7c3f-0eab-5356-a16e-3d65863eb612

STIX ID: report--fafc7c3f-0eab-5356-a16e-3d65863eb612

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-07-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A new Go-based ransomware-as-a-service called Eldorado was observed in March, with locker variants for Windows and VMware ESXi and 16 claimed victims across U.S. real estate, education, healthcare, and manufacturing. Eldorado uses ChaCha20 for per-file encryption with RSA-OAEP-wrapped keys, encrypts SMB network shares, deletes Windows shadow copies, and offers affiliate customization (e.g., target directories, network subnets, self-deletion control), making it a high-impact, actively used ransomware operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.