logo

Analysis of Elpaco: a Mimic variant

ID: cd8b1999-73f2-5803-9b23-38cf5a5fee4c

STIX ID: report--cd8b1999-73f2-5803-9b23-38cf5a5fee4c

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2024-11-26

Date Updated: 2026-04-29

Author: Cristian Souza, Timofey Ezhov, Eduardo Ovalle, Ashley Muñoz

...
...

Elpaco is a Mimic-family ransomware variant analyzed here: attackers gain access via RDP brute force, escalate privileges (Zerologon/CVE-2020-1472), deploy a dropper that abuses the legitimate Everything DLL for file discovery, and run a configurable GUI/console that customizes encryption, disables defenses, and self-deletes; the sample uses per-file X25519 key agreement and ChaCha20 encryption, leaves YARA-detectable artifacts, and has been observed in multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.