A new ransomware-as-a-service (RaaS) operation called Eldorado emerged in March 2024, targeting both Windows and VMware ESXi systems. Cybersecurity company Group-IB has reported on this threat after monitoring its activity.
Key points about Eldorado:
Targets: The gang has claimed 16 victims, primarily in the United States, across real estate, education, healthcare, and manufacturing sectors.
Platform: Eldorado is a Go-based ransomware with variants for both Windows and Linux platforms, including 32/64-bit versions for VMware ESXi hypervisors.
Encryption: The malware uses the ChaCha20 algorithm for file encryption, generating unique keys and nonces for each locked file. These are then encrypted using RSA with OAEP.
File Impact: Encrypted files are appended with the ".00000001" extension, and ransom notes titled "HOW_RETURN_YOUR_DATA.TXT" are placed in the Documents and Desktop folders.
Additional Features:
Encrypts network shares using SMB protocol
Deletes shadow volume copies on Windows
Skips certain file types and directories to maintain system functionality
Self-deletes by default to evade detection
Customization: Affiliates can customize attack parameters, especially on Windows systems.
Promotion: Eldorado operators have been promoting the service on RAMP forums and seeking skilled affiliates.
Group-IB researchers emphasize that Eldorado is a new, standalone operation and not a rebrand of an existing group. They recommend standard ransomware defense measures, including implementing multi-factor authentication, using Endpoint Detection and Response (EDR) solutions, regular data backups, and employee education on cybersecurity threats.




