ElDorado is a ransomware-as-a-service (RaaS) group that emerged in March 2024 and later rebranded as BlackLock. The group's primary motivation is financial gain, achieved through double extortion tactics that involve encrypting victims' data and exfiltrating sensitive information with threats of public release. ElDorado is distinguished by its use of a highly effective, custom-built ransomware written in Golang, designed to target both Windows and Linux systems. A Russian-speaking representative advertised the RaaS offering on cybercriminal forums to recruit affiliates, indicating a structured criminal operation rather than a loose collective.
Tecnicas MITRE
T1027, T1059.001, T1074.001, T1486, T1552, T1490
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
United Arab EmiratesArgentinaCanadaCongo, the Democratic Republic of theSpainFranceUnited KingdomCroatiaItalyJapan
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingOther Information ServicesEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationAdministrative &Waste Management