Skip to content

Eldorado

Eldorado is a ransomware family active in the mid-2020s and associated with operators involved in repeated rebranding activity, including links to Blacklock and later Mamona/Global branding.

Profile source: Mallory opens in a new tab

Eldorado

Family profile

Eldorado is a ransomware family active in the mid-2020s and associated with operators involved in repeated rebranding activity, including links to Blacklock and later Mamona/Global branding. It is part of the broader trend of fragmented ransomware operations and has been identified among newer families that emerged as the ransomware ecosystem diversified.

Eldorado has been cited as one of the ransomware strains developed to target Linux-based virtualization infrastructure, specifically VMware ESXi environments. In that role, it aligns with the growing use of Linux lockers designed to encrypt hypervisors and disrupt multiple hosted virtual machines at once, a tactic favored for high-impact enterprise extortion. This places Eldorado within the set of ransomware families focused on enterprise and virtualized infrastructure rather than only conventional Windows endpoints.

Available reporting supports classifying Eldorado as ransomware, but provides limited high-confidence detail on its distinct delivery chain, encryption workflow, or post-compromise tradecraft beyond its association with ESXi-focused operations and operator overlap with other ransomware brands. No specific initial access vector, victimology, or sector specialization is established at high confidence from the available information.

Capabilities

  • Extortion

Operational record

1
YARA rules
2
Ransom notes
1
Leak sites
0 available

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.