Cyber Security News

New Mimic Ransomware Abuses Windows Search Engine to Look Files for Encryption

A new strain of ransomware named Mimic has been uncovered recently by security experts at Trend Micro in June 2022. Mimic takes advantage of the APIs of the ‘Everything’ a file search tool for Windows to search for files to encrypt.

Users who speak English or Russian appear to be the main targets of the malware. There are similarities between some of the code in Mimic and the code found in Conti, whose source was leaked to a Ukrainian researcher in March 2022.

Mimic is a sophisticated malware, with a range of abilities including the elimination of shadow copies, shutting down various applications and services, and exploiting the Everything32[.]dll functions to identify files for encryption.

Mimic Ransomware Components

The initial stage of a Mimic ransomware attack involves the victim receiving an executable, likely through email. On the target system, the executable extracts a total of four files, which include: 

  • The main payload
  • Ancillary files
  • Tools to disable Windows Defender
Mimic Ransomware Abuses Windows Engine

Mimic is a highly adaptable strain of ransomware that can target specific files using command-line arguments and it has the ability to encrypt data at a faster rate by utilizing multiple processor threads.

Here below we have mentioned the components of Mimic:-

  • 7za[.]exe: Legitimate 7zip file that is used to extract the payload
  • Everything[.]exe: Legitimate Everything application
  • Everything32[.]dll: Legitimate Everything application
  • Everything64[.]dll: Password-protected archive that contains the malicious payloads

Capabilities of Mimic

There are several different capabilities that the new ransomware family possesses that are seen in modern strains of ransomware. 

Here below we have mentioned all the capabilities of the Mimic ransomware:-

  • Collecting system information
  • Creating persistence via the RUN key
  • Bypassing User Account Control (UAC)
  • Disabling Windows Defender
  • Disabling Windows telemetry
  • Activating anti-shutdown measures
  • Activating anti-kill measures
  • Unmounting Virtual Drives
  • Terminating processes and services
  • Disabling sleep mode and shutdown of the system
  • Removing indicators
  • Inhibiting System Recovery

Mimic ransomware uses a tactic of shutting down processes and services to remove any security barriers and gain access to crucial information.

Mimic malware employs the search function of ‘Everything’ by utilizing the ‘Everything32[.]dll’ file dropped during the initial infection, to scan the infected system for specific file names and types.

The use of ‘Everything’ allows Mimic to identify files that are suitable for encryption, without risking the locking of system files that could cause the system to become unbootable.

Mimic’s algorithm meticulously scours through all files, precisely identifying those that are suitable for encryption while skillfully bypassing any system files that could potentially cause the system to fail during startup.

Here below we have presented the Mimic ransomware config:-

In the case of encrypted files, the file extension of the encrypted files is “.QUIETPLACE”. 

The perpetrator leaves a message as a ransom note, demanding payment in Bitcoin in exchange for the safe return of the locked data, with instructions on how to proceed with the transaction.

The emergence of Mimic, a novel variant, has yet to be fully evaluated in terms of its actions, however, the utilization of the Conti builder and the Everything API demonstrates that the creators possess a proficient level of software development expertise and a solid comprehension of their objectives.

Network Security Checklist – Download Free E-Book

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago