New Ransomware-as-a-Service 'Eldorado' Targets Windows and Linux Systems
ID: 9386f8ac-7069-5b69-9aa2-320c6ef1506c
STIX ID: report--9386f8ac-7069-5b69-9aa2-320c6ef1506c
Feed Name: The Hacker News
A newly observed ransomware-as-a-service called Eldorado (first advertised March 16, 2024) delivers Golang-built, cross-platform encryptors (esxi/esxi_64/win/win_64) that use ChaCha20 for file encryption and RSA-OAEP for key encryption, can spread over SMB, and has an active leak site listing victims; the report also highlights related ransomware activity (Mallox Linux variants), a DoNex decryptor released by Avast, cleanup techniques (PowerShell shredding), and broader ransomware trends with 470 attacks reported in May 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
