Eldorado Ransomware Targets Windows and Linux, Experts Advise Caution

06 Jul 2024

Encrypting Windows and Linux

Eldorado is a Go-based ransomware that can encrypt both Windows and Linux platforms through two distinct variants with extensive operational similarities. The researchers obtained from the developer an encryptor, which came with a user manual saying that there are 32/64-bit variants available for VMware ESXi hypervisors and Windows. Group-IB says that Eldorado is a unique development “and does not rely on previously published builder sources.” The malware uses the ChaCha20 algorithm for encryption and generates a unique 32-byte key and 12-byte nonce for each of the locked files. The keys and nonces are then encrypted using RSA with the Optimal Asymmetric Encryption Padding (OAEP) scheme. After the encryption stage, files are appended the “.00000001” extension and ransom notes named “HOWRETURNYOUR_DATA.TXT” are dropped in the Documents and Desktop folders.

The Eldorado ransom noteSource: Group-IB

Eldorado also encrypts network shares utilizing the SMB communication protocol to maximize its impact and deletes shadow volume copies on the compromised Windows machines to prevent recovery. The ransomware skips DLLs, LNK, SYS, and EXE files, as well as files and directories related to system boot and basic functionality to prevent rendering the system unbootable/unusable. Finally, it’s set by default to self-delete to evade detection and analysis by response teams. According to Group-IB researchers, who infiltrated the operation, affiliates can customize their attacks. For instance, on Windows they can specify which directories to encrypt, skip local files, target network shares on specific subnets, and prevent self-deletion of the malware. On Linux, though, customization parameters stop at setting the directories to encrypt.

Defense Recommendations

Group-IB highlights that the Eldorado ransomware threat is a new, standalone operation that did not emerge as a rebrand of another group. “Although relatively new and not a rebrand of well-known ransomware groups, Eldorado has quickly demonstrated its capability within a short period of time to inflict significant damage to its victims’ data, reputation, and business continuity.” – Group-IB

The researchers recommend the following defenses, which can help protect against all ransomware attacks, to a degree:

  • Implement multi-factor authentication (MFA) and credential-based access solutions.
  • Use Endpoint Detection and Response (EDR) to quickly identify and respond to ransomware indicators.
  • Take data backups regularly to minimize damage and data loss.
  • Utilize AI-based analytics and advanced malware detonation for real-time intrusion detection and response.
  • Prioritize and periodically apply security patches to fix vulnerabilities.
  • Educate and train employees to recognize and report cybersecurity threats.
  • Conduct annual technical audits or security assessments and maintain digital hygiene.
  • Refrain from paying ransom as it rarely ensures data recovery and can lead to more attacks.

How many 1959 Cadillac Eldorado Biarritz were made?

In 1959, Cadillac produced a limited number of Eldorado Biarritz convertibles. The exact production number for the 1959 Cadillac Eldorado Biarritz was 1,320 units, making it a rare and highly sought-after classic car.

How much is a 1970 Cadillac Eldorado worth?

The value of a 1970 Cadillac Eldorado can vary widely based on its condition, mileage, originality, and specific market demand. As of now, the price range for a 1970 Cadillac Eldorado in good condition generally falls between $10,000 and $30,000, but fully restored or exceptionally well-preserved examples can fetch higher prices.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508553
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735311
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746713
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
495630
downloads

News and reviews for Desktop Windows

Visio 2021 Professional Now $9.97 Until February 8

Microsoft offers Visio 2021 Professional for $9.97, down from $249, with added templates, until February 8.

Read more

Code Vein Offers Stylish Combat, Discounted Editions

Code Vein captivates with anime-style combat and offers discounted editions. Fast-paced action meets fun builds in this cult classic.

Read more

Microsoft Phases Out RC4 in Kerberos for Windows Security

Microsoft to eliminate RC4 in Kerberos by July 2026, enhancing Windows security.

Read more

Highguard Faces Criticism but Shows Potential for Growth

Highguard, launched with controversy, holds potential despite poor reviews. Offering genre innovation, it aims to evolve against negative feedback.

Read more

PS2Recomp Boosts Native PS2 Games with Recompilation

PS2Recomp, a new tool, promises enhanced native PS2 game ports, sparking interest among developers for PC platforms.

Read more

NVIDIA Introduces RTX Remix Logic for Classic Game Mods

NVIDIA's RTX Remix Logic, launched on 2026-01-27, enables dynamic modding of classic PC games with a no-code node-based interface.

Read more

Windows 11 Update KB5074109 Affects Legacy Modems

The Windows 11 update KB5074109 disrupts modems by removing several legacy drivers, causing connectivity issues for select users.

Read more

Anytype Replaces Notion, Obsidian, and Todoist for Unified Workflow

Anytype consolidates Notion, Obsidian, and Todoist functions, reducing context-switching and improving workflow efficiency.

Read more

ReBlade: Cyberpunk Roguelike Announced by ChillyRoom

ReBlade from ChillyRoom and Spiral Up Games announced for PC: cyberpunk roguelike offers high-speed action in a dystopian setting.

Read more

Artorias Battles Elden Ring Bosses in New Video Showcase

Artorias from Dark Souls faces Elden Ring bosses, demonstrating impressive skills in Fights' YouTube video.

Read more