Eldorado
Eldorado is a ransomware family active in the mid-2020s and associated with operators involved in repeated rebranding activity, including links to Blacklock and later Mamona/Global branding.
Profile source: Mallory opens in a new tabEldorado
Family profile
Eldorado is a ransomware family active in the mid-2020s and associated with operators involved in repeated rebranding activity, including links to Blacklock and later Mamona/Global branding. It is part of the broader trend of fragmented ransomware operations and has been identified among newer families that emerged as the ransomware ecosystem diversified.
Eldorado has been cited as one of the ransomware strains developed to target Linux-based virtualization infrastructure, specifically VMware ESXi environments. In that role, it aligns with the growing use of Linux lockers designed to encrypt hypervisors and disrupt multiple hosted virtual machines at once, a tactic favored for high-impact enterprise extortion. This places Eldorado within the set of ransomware families focused on enterprise and virtualized infrastructure rather than only conventional Windows endpoints.
Available reporting supports classifying Eldorado as ransomware, but provides limited high-confidence detail on its distinct delivery chain, encryption workflow, or post-compromise tradecraft beyond its association with ESXi-focused operations and operator overlap with other ransomware brands. No specific initial access vector, victimology, or sector specialization is established at high confidence from the available information.
Capabilities
- Extortion