Mimic is a Windows ransomware family first observed in June 2022. It encrypts local and network-accessible files, presents ransom demands, deletes shadow copies, terminates processes and services, and impairs recovery and security controls. Mimic uses Voidtools Everything search APIs to rapidly enumerate files selected for encryption and uses multithreaded execution to accelerate encryption. It can collect host information, enumerate network shares, conduct local-network discovery and port-scanning activity, establish Windows startup persistence, and remove artifacts after execution. Mimic incorporates code and design similarities associated with the leaked Conti ransomware builder. Variants, including Elpaco, provide configurable encryption scope, exclusions, ransom-note content, process termination, and command execution; analyzed variants use per-file asymmetric-key protection with ChaCha20-based encryption. Mimic has been deployed against poorly secured, internet-exposed Microsoft SQL Server environments following credential attacks, including campaigns attributed to the Trigona-related/Larva-26002 activity cluster and financially motivated operators assessed to have a Turkish nexus. The Pay2Key ransomware is based on Mimic.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
After that, the adversary was able to elevate their privileges by exploiting the CVE-2020-1472 vulnerability (Zerologon).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January 2024, the group first made its mark by deploying Trigona and Mimic ransomware on MS-SQL servers exposed to the internet with weak credentials.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
In the GUI, the operator can select entire drives for encryption, perform a process injection to hide malicious processes...
After that, the adversary was able to elevate their privileges by exploiting the CVE-2020-1472 vulnerability (Zerologon).
Mimic arrives with a password-protected archive, disguised as Everything64.dll, which contains the ransomware payload.
The password-protected archive is disguised as Everything64.dll, and the ransomware is renamed to bestplacetolive.exe after being copied to a random LocalAppData GUID directory.
In the GUI, the operator can select entire drives for encryption, perform a process injection to hide malicious processes...
Mimic copies dropped files to %LocalAppData%\{Random GUID}\, renames the ransomware, and deletes the original files from the %Temp% directory; its capabilities also include removing indicators.
The folder that is ultimately installed not only contains Mimic ransomware and the Everything tool, but also... the SDelete tool (xdel.exe) of Sysinternals.
Mimic drops a password-protected archive disguised as Everything64.dll and extracts it with 7za.exe using a hard-coded password.
Another feature of Elpaco is that it deletes itself after encrypting files to evade detection and analysis. The last step in malware execution is calling the Del command to delete all executables... before deleting, the sample uses the fsutil LOLBin... to securely erase svhostss.exe
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
For its net argument, Mimic uses GetIpNetTable to read the ARP cache and checks IP addresses in private network ranges before conducting Windows share enumeration.
The commands that the threat actor first executes before creating the malware with BCP... are those that look up the infected system’s information as shown below. > hostname > whoami
Mimic’s port-scanning functionality is based on the leaked Conti builder.
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
Mimic ransomware possesses a plethora of capabilities, including: Collecting system information.
Mimic includes tools used for turning off Windows Defender and capabilities for disabling Windows Defender, disabling Windows telemetry, terminating processes and services, and activating anti-kill measures.
The folder that is ultimately installed not only contains Mimic ransomware and the Everything tool, but also the Defender Control tool (DC.exe) for deactivating Windows Defender
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows ransomware that uses multithreaded encryption and abuses the legitimate Everything filename-search APIs to efficiently enumerate target files. It appends the .QUIETPLACE extension to encrypted files, displays a ransom note, can disable Windows Defender and telemetry, establish Run-key persistence, bypass UAC, inhibit recovery, remove indicators, terminate processes and services, and enumerate network shares.
Ransomware manually deployed after MSSQL server compromise and lateral movement. In this campaign it was delivered as red25.exe, which extracted red.exe, used the legitimate Everything utility to locate files, encrypted hosts including the MSSQL server and domain controller, and dropped a ransom note.
Mimic5
Семейство вымогательского ПО, на котором основан Pay2Key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.