New Ransomware Variant “Eldorado” Unleashed, Focused on VMware ESXi Systems

New Ransomware Variant “Eldorado” Unleashed, Focused on VMware ESXi Systems

A new ransomware-as-a-service called Eldorado has been targeting Windows and VMware ESXi environments in the US since March, primarily in the education, real estate, and healthcare sectors. Eldorado, which first appeared on the RAMP forum, offers an affiliate program for partners to customize their attacks, taking advantage of Go programs for cross-platform functionality and encryption … Read more

SecurityWeek: VMware addresses critical vulnerabilities allowing sandbox escape in ESXi

VMware has recently addressed critical vulnerabilities in its ESXi virtualization platform that could allow attackers to escape from the sandboxed environment. These vulnerabilities were highlighted during Safety Week, a global initiative focused on raising awareness about the importance of cybersecurity. VMware acted promptly to release patches for these vulnerabilities, ensuring that users can continue to … Read more

VMware ESXi and Windows Infected by Eldorado Ransomware, Reports Spiceworks

VMware ESXi and Windows Infected by Eldorado Ransomware, Reports Spiceworks

A cybersecurity research team has identified a new ransomware called Eldorado that is targeting organizations globally. This ransomware is operated as Ransomware-as-a-Service (RaaS), allowing for decentralized deployment and a wider range of malware variants. The Eldorado ransomware encrypts files using the ChaCha20 algorithm and employs the RSA-OAEP scheme for key encryption. RaaS enables customers to … Read more

New Eldorado ransomware now targeting Windows and VMware ESXi VMs

New Eldorado ransomware now targeting Windows and VMware ESXi VMs

In March, a new ransomware called Eldorado, operating as a service (RaaS), has targeted victims in the United States across various sectors such as real estate, education, healthcare, and manufacturing. The cybercriminals behind Eldorado have been actively promoting their service on RAMP forums and seeking partners to join their program. Eldorado is a unique ransomware … Read more

New Eldorado ransomware now seeking out Windows and VMware ESXi virtual machines

New Eldorado ransomware now targeting Windows and VMware ESXi VMs

In March, a new ransomware called Eldorado emerged, targeting victims in the US across various industries. The cybercriminals behind Eldorado are actively promoting their malicious service on forums and seeking partners to join their program. The ransomware can encrypt both Windows and Linux systems using different variants and unique encryption algorithms. It also deletes shadow … Read more

Hackers Utilize Linux Rootkits to Conceal Themselves on VMware ESXi Virtual Machines in UNC3886

In a recent cybersecurity threat, hackers identified as UNC3886 have been using Linux rootkits to conceal their presence on VMware ESXi virtual machines (VMs). This method allows the hackers to remain undetected while gaining unauthorized access to sensitive information. Rootkits are a type of malware that hide their presence within a system, making it difficult … Read more

Attackers can bypass authentication on VMware ESXi due to vulnerability

Attackers can bypass authentication on VMware ESXi due to vulnerability

VMware has disclosed three critical vulnerabilities in its ESXi hypervisor that could allow attackers to bypass authentication mechanisms. These vulnerabilities, identified as CVE-2024-37085, CVE-2024-37086, and CVE-2024-37087, pose significant risks to organizations utilizing VMware ESXi in their virtualized environments. The vulnerabilities impact the authentication processes within VMware ESXi, potentially enabling unauthorized access to the system. CVE-2024-37085 … Read more