Mimic is a Windows ransomware family derived from the leaked Conti codebase. It is designed to enumerate files, encrypt victim data, and present ransom instructions, and has been observed in multiple variants including Elpaco as well as derivative operations such as Pay2Key builds based on Mimic. A notable implementation detail is its abuse of the legitimate Voidtools Everything search components and APIs to accelerate filesystem discovery and identify files for encryption. Reported variants also support multi-threaded encryption, configurable targeting and exclusions, process and service termination to unlock files, and operator-controlled customization through a graphical interface.
Observed Mimic variants use modern file-encryption workflows, including per-file asymmetric key exchange with X25519 or Curve25519 and symmetric encryption with ChaCha20, with session state preserved to allow interrupted encryption runs to resume. Some builds establish persistence through Windows startup mechanisms and file-association changes that ensure ransom notes are displayed after reboot. Defense evasion has included disabling Microsoft Defender with third-party utilities, packaging payloads in self-extracting or password-protected archives, and deleting artifacts after execution.
Mimic has been deployed following brute-force compromise of exposed services, especially RDP and internet-facing Microsoft SQL Server instances with weak credentials. In documented intrusions, attackers used post-compromise tooling such as Impacket, remote administration software, and SQL Server utilities to stage payloads and maintain access before launching ransomware. Activity involving Mimic has been linked to financially motivated operators and affiliates, including campaigns associated with Trigona-related MS-SQL intrusions and later ransomware operations built on Mimic code. Victims have included organizations across multiple countries and sectors, with repeated targeting of Windows servers and enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
After that, the adversary was able to elevate their privileges by exploiting the CVE-2020-1472 vulnerability (Zerologon).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January 2024, the group first made its mark by deploying Trigona and Mimic ransomware on MS-SQL servers exposed to the internet with weak credentials.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
In the GUI, the operator can select entire drives for encryption, perform a process injection to hide malicious processes...
After that, the adversary was able to elevate their privileges by exploiting the CVE-2020-1472 vulnerability (Zerologon).
The most interesting artifact is svhostss.exe, which is the main console used by the malware. It is worth mentioning that this name closely mimics svchost.exe, a legitimate Windows process.
In the GUI, the operator can select entire drives for encryption, perform a process injection to hide malicious processes...
Another feature of Elpaco is that it deletes itself after encrypting files to evade detection and analysis. The last step in malware execution is calling the Del command to delete all executables... before deleting, the sample uses the fsutil LOLBin... to securely erase svhostss.exe
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
The Mimic ransomware searches for specific files using Everything APIs, encrypts user data... In the GUI, the operator can select entire drives for encryption...
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mimic5
Семейство вымогательского ПО, на котором основан Pay2Key.
Ransomware family and codebase derivative of Conti. The analyzed Pay2Key encryptor is built on Mimic and inherits features such as Everything-based file enumeration and other codebase elements.
Ransomware used in 2024 attacks on poorly secured MS-SQL servers; the Turkish strings in ICE Cloud are described as directly tying the 2026 campaign to the Mimic ransomware attacks from 2024.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.