Cyber Security

New Elpaco Ransomware Actors Connect Via RDP To Deploy Ransomware

Elpaco ransomware, a Mimic variation, has been identified where attackers were able to connect via RDP to the victim’s server following a successful brute force attack and subsequently execute the ransomware.

The variant abuses the Everything DLL, which is used for file discovery and gives the attacker a user-friendly graphical user interface (GUI) to customize the malware’s actions. 

Further, it also provides tools for executing system instructions and turning off security measures.

The Attackers’ Tactics, Techniques, And Procedures (TTPs)

The sample was revealed to have abused the Everything library, a legitimate filename search engine that offers quick searches and real-time updates by indexing files on Windows PCs.

Similar to the Mimic ransomware that TrendMicro had previously identified, the artifact exploited this library by including malicious payloads in a password-protected package called Everything64.dll and legitimate Everything apps (Everything32.dll and Everything.exe).

Analyze cyber threats with ANYRUN's powerful sandbox. Black Friday Deals : Get up to 3 Free Licenses.

The remaining file inside the package was a legitimate 7-Zip utility that could extract the malicious archive contents. 

7-Zip extraction command

Upon execution, the malware unpacked the archive and placed the required files in a different directory called %AppData%\Local, which had a randomly generated UUID as its name.

According to Kaspersky, using Everything APIs, the Mimic ransomware looks for specific files, encrypts user information, requests ransom payments, and uses advanced features like multi-threaded encryption to speed up the attack.

Additionally, Mimic evades detection by obfuscating its code, making it more difficult for security tools to identify and terminate the attack.

The archive contents are necessary to encrypt files and conduct other operating system functions.

The Defender Control tool, for instance, is the DC.exe file, which is used to enable and disable Windows Defender. Once unpacked, the sample initiates it.

Elpaco structure

The malware’s primary console, svhostss.exe, is the most interesting artifact, too. It is important to note that this name closely resembles the real Windows process svchost.exe. 

During memory analysis, threat actors frequently employ this naming pattern to confuse less knowledgeable people. 

In the same directory, the malware includes a GUI titled gui40.exe. Through console interaction, it makes it easier to carry out tasks like modifying ransomware features, such a ransom note or permitted directories/files, and taking action on the target machine.

“In the GUI, the operator can select entire drives for encryption, perform a process injection to hide malicious processes, customize the ransom note, change the encryption extension, set the order of encryption based on the original file format, and exclude specific directories, files or formats from encryption”, the researchers said.

Ransom note customization

It is also possible to execute system commands and kill specific processes that the operator specifies, making this threat extremely customizable.

Ransomware parameters

The Elpaco and Mimic variants look at the victim’s files using the SetSearchW function, which is exported from the legitimate Everything DLL.

SetSearchW function

Using the Del command to remove all executables, configuration files, DLLs, batch files, and database-related items from the ransomware directory is the final stage of malware execution.

It’s interesting to note that the sample safely deletes the svhostss.exe file without any chance of recovery.

Elpaco samples and other Mimic variants are mainly targeted at the United States, Russia, the Netherlands, Germany, and France.

According to researchers, the encryption mechanism prevents decrypting files on an infected machine without the private key, making this threat difficult to deal with. Elpaco also has the ability to erase files after encryption to avoid detection and analysis. 

Large-scale attacks using Elpaco and other mimic samples have been reported recently, affecting numerous nations throughout the globe.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago