El Dorado is a financially motivated ransomware-as-a-service (RaaS) operation that emerged in March 2024 and recruited penetration testers and affiliates through the RAMP cybercriminal forum. In September 2024, it rebranded as BlackLock and continued operating. BlackLock Blog and Mamona Blog have also been identified as related El Dorado-branded leak-site variants operated by the same actor. The operation has used dedicated leak sites as part of its extortion model and has advertised and recruited within the Russian-language ransomware ecosystem. El Dorado has developed Linux ransomware payloads intended to encrypt VMware ESXi environments and has been associated with targeting industrial and critical-infrastructure organizations. It has also appeared in ransomware leak-site reporting involving healthcare entities, although individual leak-site victim claims require independent validation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with healthcare-sector dedicated leak-site postings.
Eldorado is a ransomware group present on RAMP, engaging in recruitment and the sharing of ransomware tactics and intelligence.
Parent ransomware lineage referenced through derivative brands involved in inter-group rivalry and extortion-site targeting.
Ransomware operation noted for Linux lockers tailored to VMware ESXi, encrypting VM files and disrupting operations with minimal dwell time.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.