◇ SIGN IN
← all actors
ransomware

Eldorado

defunctmedium confidence
Ransomware
ElDoradoEl DoradoBlackLock (successor rebrand)
Attribution
RaaS
Origin
Unknown
First seen
2024
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Jordan, Lebanon, UAE
Sectors
Technology/software, construction materials, facility services

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Jordan, Lebanon, UAE (Technology/software, construction materials, facility services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Eldorado was a ransomware-as-a-service operation that launched in March 2024 with a Go-based cross-platform encryptor for Windows and Linux/ESXi; it was later rebranded as BlackLock and went inactive under the Eldorado name by early 2025.

History

Eldorado surfaced on 16 March 2024 when an affiliate-program advertisement was posted on the RAMP ransomware forum. Group-IB and others analyzed its Golang-based encryptor, which used ChaCha20 for file encryption and RSA-OAEP for key protection and shipped in ESXi, ESXi_64, Win and Win_64 builds, giving it cross-platform reach against enterprise and virtualization infrastructure.

By June 2024 its leak site listed around 16 victims, predominantly in the United States, and one tracker credited the group with roughly 112 total victims before it went inactive. Reporting indicates Eldorado was rebranded as 'BlackLock' later in 2024, with the Eldorado brand becoming inactive around January 2025.

Eldorado operated a conventional double-extortion RaaS model; it is not established as a rebrand of RansomHub, which reporting treats as a separate operation. Its MENA-relevant claims include Jordan, Lebanon and the UAE. All leak-site listings are extortion claims and should be treated as unverified unless confirmed by a reputable source or the affected organization.

Notable campaigns

2024
Eldorado RaaS debut
Launched March 2024 on RAMP with a Go-based Windows/Linux/ESXi encryptor; ~16 leak-site victims by June 2024.
2024
Rebrand to BlackLock
Reportedly rebranded as BlackLock later in 2024; Eldorado brand inactive by early 2025 (claimed lineage).

Claimed victims · 112 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
Rees NDT Inspection ServicesCAManufacturing
EVAS GroupCAProfessional Services
Inventory Management and Counting SolutionsUSProfessional Services
HIDROCARBUROS ARGENTINOS S.A.AREnergy & Utilities
Perú Controls S.A.C.PEManufacturing
D&G Enviro-GroupCAEnergy & Utilities
Relate InfotechGBTechnology
AkanthaFRTechnology
Acumen GroupUSRetail & E-Commerce
LaSenUSEnergy & Utilities
Midland TurboGBManufacturing
First Baptist ChurchUSGovernment & Defense