ElDorado logo

ElDorado

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Aliases: BlackLock
Ver en IntelTracker → APTTrail →
ElDorado is a ransomware-as-a-service (RaaS) group that emerged in March 2024 and later rebranded as BlackLock. The group's primary motivation is financial gain, achieved through double extortion tactics that involve encrypting victims' data and exfiltrating sensitive information with threats of public release. ElDorado is distinguished by its use of a highly effective, custom-built ransomware written in Golang, designed to target both Windows and Linux systems. A Russian-speaking representative advertised the RaaS offering on cybercriminal forums to recruit affiliates, indicating a structured criminal operation rather than a loose collective.
Tecnicas MITRE
T1027, T1059.001, T1074.001, T1486, T1552, T1490

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
77
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaCanadaCongo, the Democratic Republic of theSpainFranceUnited KingdomCroatiaItalyJapan

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationAdministrative &Waste Management