el dorado
0 incidentes
0 paises
0 sectores
ransomware RU Ultimo: -
Aliases: El-Dorado, Global, BlackLock, Eldorado, El Dorado Doxware, Blacklock
El Dorado is a Ransomware-as-a-Service (RaaS) operation that first emerged in March 2024, publicly advertising its affiliate program on the RAMP forum. The group, which rebranded to BlackLock around September 2024, is believed to be of Russian origin, with its representatives communicating in Russian. El Dorado's primary motivation is financial gain through double extortion, encrypting victim data and threatening to leak or sell exfiltrated sensitive information if a ransom is not paid. A key characteristic that differentiates El Dorado is its custom-developed ransomware builder, written in Golang, which supports cross-platform targeting of Windows, Linux, and VMware ESXi environments, and does not rely on previously leaked ransomware source codes. The RaaS model allows affiliates to customize various attack parameters, enhancing its operational flexibility.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
Paises objetivo (SOCRadar)
United Arab Emirates
Argentina
AustraliaAruba
BelgiumBermuda
Brazil
CanadaCongo, the Democratic Republic of theCongo
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturingConstruction