Mimic is a Windows ransomware family first observed in June 2022, with infections affecting Russian- and English-speaking users. It encrypts local files and network-share data and demands payment for recovery. Its code incorporates functionality from the leaked Conti ransomware builder, including network discovery, share enumeration, port scanning, and encryption-mode logic.
Mimic bundles and abuses voidtools’ legitimate Everything file-search utility to rapidly locate files matching configured encryption criteria. It supports multithreaded encryption, configurable targeting and exclusions, and session state that allows encryption to resume after interruption. Distribution packages use self-extracting archives containing legitimate utilities and a password-protected payload archive disguised as a DLL. The ransomware gathers system information, establishes startup persistence, bypasses User Account Control, disables Windows Defender and telemetry, terminates processes and services, deletes shadow copies, and impairs recovery. Anti-termination and anti-shutdown mechanisms help sustain encryption, while artifact removal hinders investigation.
Mimic has been deployed against internet-exposed Microsoft SQL Server instances protected by weak credentials. Operators gain access through brute-force or dictionary attacks, execute operating-system commands through SQL Server functionality, and deliver ransomware using remote administration tools or the SQL Server Bulk Copy Program to export payloads from database tables. Campaigns have included deployment to domain controllers and other domain-joined systems after credential theft and lateral movement using separate tools. Associated activity includes RE#TURGENCE, Larva-26002, and operators also deploying Trigona ransomware. Elpaco is a Mimic variant with an operator-facing configuration interface and per-file encryption using X25519 key exchange and ChaCha20.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
After that, the adversary was able to elevate their privileges by exploiting the CVE-2020-1472 vulnerability (Zerologon).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our research, we didn't see Earth Lamia use any ransomware.
In January 2024, the group first made its mark by deploying Trigona and Mimic ransomware on MS-SQL servers exposed to the internet with weak credentials.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
In the GUI, the operator can select entire drives for encryption, perform a process injection to hide malicious processes...
After that, the adversary was able to elevate their privileges by exploiting the CVE-2020-1472 vulnerability (Zerologon).
Mimic arrives with a password-protected archive, disguised as Everything64.dll, which contains the ransomware payload.
The password-protected archive is disguised as Everything64.dll, and the ransomware is renamed to bestplacetolive.exe after being copied to a random LocalAppData GUID directory.
In the GUI, the operator can select entire drives for encryption, perform a process injection to hide malicious processes...
Mimic copies dropped files to %LocalAppData%\{Random GUID}\, renames the ransomware, and deletes the original files from the %Temp% directory; its capabilities also include removing indicators.
The folder that is ultimately installed not only contains Mimic ransomware and the Everything tool, but also... the SDelete tool (xdel.exe) of Sysinternals.
Mimic drops a password-protected archive disguised as Everything64.dll and extracts it with 7za.exe using a hard-coded password.
Another feature of Elpaco is that it deletes itself after encrypting files to evade detection and analysis. The last step in malware execution is calling the Del command to delete all executables... before deleting, the sample uses the fsutil LOLBin... to securely erase svhostss.exe
The malware creates the following registry keys... Also, the artifact configures the Run registry key to execute svhostss.exe and display the ransom note at startup.
Mimic includes tools used for turning off Windows Defender and capabilities for disabling Windows Defender, disabling Windows telemetry, terminating processes and services, and activating anti-kill measures.
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
For its net argument, Mimic uses GetIpNetTable to read the ARP cache and checks IP addresses in private network ranges before conducting Windows share enumeration.
The commands that the threat actor first executes before creating the malware with BCP... are those that look up the infected system’s information as shown below. > hostname > whoami
Mimic’s port-scanning functionality is based on the leaked Conti builder.
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
Mimic ransomware possesses a plethora of capabilities, including: Collecting system information.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows ransomware that uses multithreaded encryption and abuses the legitimate Everything filename-search APIs to efficiently enumerate target files. It appends the .QUIETPLACE extension to encrypted files, displays a ransom note, can disable Windows Defender and telemetry, establish Run-key persistence, bypass UAC, inhibit recovery, remove indicators, terminate processes and services, and enumerate network shares.
Ransomware manually deployed after MSSQL server compromise and lateral movement. In this campaign it was delivered as red25.exe, which extracted red.exe, used the legitimate Everything utility to locate files, encrypted hosts including the MSSQL server and domain controller, and dropped a ransom note.
Mimic5
Семейство вымогательского ПО, на котором основан Pay2Key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.