ElDorado Ransomware Strikes BUROTEC S.A. - Data Theft and Dark Web Sale

Incident Date:

June 6, 2024

World map

Overview

Title

ElDorado Ransomware Strikes BUROTEC S.A. - Data Theft and Dark Web Sale

Victim

BUROTEC S.A.

Attacker

ElDorado

Location

Pointe-Noire, Congo

, Congo

First Reported

June 6, 2024

ElDorado Ransomware Attack on BUROTEC S.A.

Overview of BUROTEC S.A.

BUROTEC S.A. is a prominent consultancy firm specializing in engineering, architecture, and environmental management. Founded in 1975, the company operates primarily in the Congolese market and has a significant presence with multiple locations, including Pointe-Noire, Congo. The firm offers a wide range of services, including structural, mechanical, and electrical engineering, as well as comprehensive architectural and environmental management solutions. Their multidisciplinary approach and commitment to quality and customer satisfaction have made them a key player in their industry.

Details of the Ransomware Attack

The ransomware group ElDorado has claimed responsibility for a recent attack on BUROTEC S.A., resulting in the theft of 120GB of sensitive data. The stolen data has been put up for sale on ElDorado's dark web leak site. The attack has significantly impacted BUROTEC, given their extensive operations and the critical nature of their services.

About ElDorado Ransomware Group

ElDorado is a ransomware group that emerged in 2024, known for its double-extortion tactics. They encrypt victims' files and exfiltrate sensitive data, threatening to release it publicly if ransom demands are not met. ElDorado has claimed 15 victims over seven months, showcasing their aggressive and sophisticated approach. They use a variety of tactics, including phishing attacks, exploiting unpatched vulnerabilities, and leveraging weaknesses in Remote Desktop Protocol (RDP) configurations.

Penetration and Impact

ElDorado's meticulous targeting and reconnaissance allowed them to identify and exfiltrate valuable data from BUROTEC's systems. The group left a ransom note named HOW_RETURN_YOUR_DATA.TXT, instructing BUROTEC to contact them via the TOR network. The attack has raised concerns about the vulnerabilities in BUROTEC's cybersecurity defenses, particularly in their ability to protect against sophisticated ransomware attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.