logo

ELENOR-corp Ransomware: A New Mimic Ransomware Variant Attacking the Healthcare Sector

ID: 6f91a6ff-8462-5763-ae8d-01c71828fdc9

STIX ID: report--6f91a6ff-8462-5763-ae8d-01c71828fdc9

Feed Name: Morphisec Blog

Threat Score
80/100

Date Published: 2025-04-24

Date Updated: 2026-04-28

Author: Michael Gorelik

...
...

Morphisec investigated a March 2025 ransomware incident involving a new Mimic v7.5 variant (ELENOR-corp) targeting a healthcare organization; the report describes initial access via a persistent Python-compiled Clipper used for credential harvesting and reentry, extensive lateral movement using RDP and tools like Mimikatz, data exfiltration to Mega.nz, sophisticated persistence, anti-forensics (DACL manipulation, shadow copy deletion, IFEO tampering), and provides file/IP hashes and C2 IOCs to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.