Eldorado is a ransomware family active in the mid-2020s and associated with operators involved in repeated rebranding activity, including links to Blacklock and later Mamona/Global branding. It is part of the broader trend of fragmented ransomware operations and has been identified among newer families that emerged as the ransomware ecosystem diversified.
Eldorado has been cited as one of the ransomware strains developed to target Linux-based virtualization infrastructure, specifically VMware ESXi environments. In that role, it aligns with the growing use of Linux lockers designed to encrypt hypervisors and disrupt multiple hosted virtual machines at once, a tactic favored for high-impact enterprise extortion. This places Eldorado within the set of ransomware families focused on enterprise and virtualized infrastructure rather than only conventional Windows endpoints.
Available reporting supports classifying Eldorado as ransomware, but provides limited high-confidence detail on its distinct delivery chain, encryption workflow, or post-compromise tradecraft beyond its association with ESXi-focused operations and operator overlap with other ransomware brands. No specific initial access vector, victimology, or sector specialization is established at high confidence from the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware strain referenced as part of a sequence of rebrands by the same operator in 2025.
Ransomware operation noted for Linux lockers tailored to VMware ESXi, encrypting VM files and disrupting operations by disabling active VMs.
Ransomware family referenced as part of 2024-era groups continuing ESXi/hypervisor targeting trends.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.