News

New Eldorado Ransomware-as-a-Service Targets Windows and VMware ESXi Systems

Giulio Saggin
Giulio Saggin
Wednesday 10 July 2024
New Eldorado Ransomware-as-a-Service Targets Windows and VMware ESXi Systems
Microsoft Windows

A new ransomware-as-a-service (RaaS) operation called Eldorado emerged in March 2024, targeting both Windows and VMware ESXi systems. Cybersecurity company Group-IB has reported on this threat after monitoring its activity.

Key points about Eldorado:

  1. Targets: The gang has claimed 16 victims, primarily in the United States, across real estate, education, healthcare, and manufacturing sectors.

  2. Platform: Eldorado is a Go-based ransomware with variants for both Windows and Linux platforms, including 32/64-bit versions for VMware ESXi hypervisors.

  3. Encryption: The malware uses the ChaCha20 algorithm for file encryption, generating unique keys and nonces for each locked file. These are then encrypted using RSA with OAEP.

  4. File Impact: Encrypted files are appended with the ".00000001" extension, and ransom notes titled "HOW_RETURN_YOUR_DATA.TXT" are placed in the Documents and Desktop folders.

  5. Additional Features:

    • Encrypts network shares using SMB protocol

    • Deletes shadow volume copies on Windows

    • Skips certain file types and directories to maintain system functionality

    • Self-deletes by default to evade detection

  6. Customization: Affiliates can customize attack parameters, especially on Windows systems.

  7. Promotion: Eldorado operators have been promoting the service on RAMP forums and seeking skilled affiliates.

Group-IB researchers emphasize that Eldorado is a new, standalone operation and not a rebrand of an existing group. They recommend standard ransomware defense measures, including implementing multi-factor authentication, using Endpoint Detection and Response (EDR) solutions, regular data backups, and employee education on cybersecurity threats.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203