Eldorado Ransomware Targets Windows and Linux, Experts Advise Caution

06 Jul 2024

Encrypting Windows and Linux

Eldorado is a Go-based ransomware that can encrypt both Windows and Linux platforms through two distinct variants with extensive operational similarities. The researchers obtained from the developer an encryptor, which came with a user manual saying that there are 32/64-bit variants available for VMware ESXi hypervisors and Windows. Group-IB says that Eldorado is a unique development “and does not rely on previously published builder sources.” The malware uses the ChaCha20 algorithm for encryption and generates a unique 32-byte key and 12-byte nonce for each of the locked files. The keys and nonces are then encrypted using RSA with the Optimal Asymmetric Encryption Padding (OAEP) scheme. After the encryption stage, files are appended the “.00000001” extension and ransom notes named “HOWRETURNYOUR_DATA.TXT” are dropped in the Documents and Desktop folders.

The Eldorado ransom noteSource: Group-IB

Eldorado also encrypts network shares utilizing the SMB communication protocol to maximize its impact and deletes shadow volume copies on the compromised Windows machines to prevent recovery. The ransomware skips DLLs, LNK, SYS, and EXE files, as well as files and directories related to system boot and basic functionality to prevent rendering the system unbootable/unusable. Finally, it’s set by default to self-delete to evade detection and analysis by response teams. According to Group-IB researchers, who infiltrated the operation, affiliates can customize their attacks. For instance, on Windows they can specify which directories to encrypt, skip local files, target network shares on specific subnets, and prevent self-deletion of the malware. On Linux, though, customization parameters stop at setting the directories to encrypt.

Defense Recommendations

Group-IB highlights that the Eldorado ransomware threat is a new, standalone operation that did not emerge as a rebrand of another group. “Although relatively new and not a rebrand of well-known ransomware groups, Eldorado has quickly demonstrated its capability within a short period of time to inflict significant damage to its victims’ data, reputation, and business continuity.” – Group-IB

The researchers recommend the following defenses, which can help protect against all ransomware attacks, to a degree:

  • Implement multi-factor authentication (MFA) and credential-based access solutions.
  • Use Endpoint Detection and Response (EDR) to quickly identify and respond to ransomware indicators.
  • Take data backups regularly to minimize damage and data loss.
  • Utilize AI-based analytics and advanced malware detonation for real-time intrusion detection and response.
  • Prioritize and periodically apply security patches to fix vulnerabilities.
  • Educate and train employees to recognize and report cybersecurity threats.
  • Conduct annual technical audits or security assessments and maintain digital hygiene.
  • Refrain from paying ransom as it rarely ensures data recovery and can lead to more attacks.

How many 1959 Cadillac Eldorado Biarritz were made?

In 1959, Cadillac produced a limited number of Eldorado Biarritz convertibles. The exact production number for the 1959 Cadillac Eldorado Biarritz was 1,320 units, making it a rare and highly sought-after classic car.

How much is a 1970 Cadillac Eldorado worth?

The value of a 1970 Cadillac Eldorado can vary widely based on its condition, mileage, originality, and specific market demand. As of now, the price range for a 1970 Cadillac Eldorado in good condition generally falls between $10,000 and $30,000, but fully restored or exceptionally well-preserved examples can fetch higher prices.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4942277
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
826041
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
418134
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
304340
downloads

News and reviews for Desktop Windows

Microsoft's Potential Handheld Gaming Plans Spark Interest

Speculation grows over a Microsoft device as a potential handheld competitor to the Steam Deck, potentially unveiled at the Xbox Games Showcase.

Read more

Hellslave RPG Available Free on Steam For Limited Time

The dark fantasy RPG Hellslave is now free on Steam, as its sequel approaches. Experience this dungeon-crawler and retain it in your library forever. Claim it by June 16.

Read more

Foxtail Unveils Hidden Gem from Comiket 81 in Gaming History

A mysterious disc titled Action RPG (Temp) C81 Demo Version reveals a rarely seen game from Comiket 81 in 2011, featuring unique stamina-based combat. The demo offers a glimpse into a creative era of RPGs, thanks to the dedicated work of developer Foxtail.

Read more

IO Interactive Unveils New James Bond Game: First Light

IO Interactive announces 007 First Light, a new video game featuring an original James Bond origin story. Players will earn their 00 status in this immersive gaming experience crafted for a fresh perspective within the Bond series.

Read more

Anvil Empires Aims to Revolutionize Medieval RTS Gaming

Anvil Empires, a medieval RTS game inspired by Age of Empires 2, offers a large-scale playtest. It combines classic strategy mechanics with MMO elements, allowing up to 1,000 players per server. The focus is on logistics and teamwork.

Read more

Atomic Heart Game Offers Up to 71% Off Sale This Year

Atomic Heart, a distinctive shooter set in a robot-dystopia, is on sale with a 71% discount. Experience the narrative of rebellion against an authoritarian regime as P-3. With elemental powers and melee combat, it promises a unique adventure at $21.09 / £15.49.

Read more

IO Interactive Reveals James Bond Game 007 First Light

IO Interactive announces 007 First Light, a new James Bond game. The long-awaited origin story adds to the Bond franchise's gaming legacy. Fans eagerly await the full reveal, marking IO Interactive's first major step since 2020.

Read more

Nightreign Patch Improves Gameplay for Singleplayer Mode

The Nightreign patch adds auto-resurrect and boosts levelling, addressing challenges in singleplayer mode. Players now experience improved balance and performance, aligning with FromSoftware's commitment to refining gameplay.

Read more

Elden Ring Patch Enhances Solo Gameplay Dynamics

Elden Ring receives a solo gameplay boost with the Nightreign patch. The update introduces automatic revival and improved rewards, enhancing gamers' experiences.

Read more

Medal of Honor Game Reimagined with Unreal Engine 5

The classic Medal of Honor Allied Assault is reimagined using Unreal Engine 5, receiving praise from original game designer Nathan Silvers. The remake highlights the enduring legacy of the game, despite the uncertain future of the Medal series.

Read more