• New Mimic Ransomware Abuses Everything APIs for its Encryption Process

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » New Mimic Ransomware Abuses Everything APIs for its Encryption Process

    Author
    Topic
    #2529320

    https://www.trendmicro.com/en_us/research/23/a/new-mimic-ransomware-abuses-everything-apis-for-its-encryption-p.html

    Trend Micro researchers discovered a new ransomware that abuses the APIs of a legitimate tool called Everything, a Windows filename search engine developed by Voidtools that offers quick searching and real-time updates for minimal resource usage. This ransomware (which we named Mimic based on a string we found in its binaries), was first observed in the wild in June 2022 and targets Russian and English-speaking users. It is equipped with multiple capabilities such as deleting shadow copies, terminating multiple applications and services, and abusing Everything32.dll functions to query target files that are to be encrypted…

    Mimic arrives as an executable that drops multiple binaries and a password-protected archive (disguised as Everything64.dll) which when extracted, contains the ransomware payload. It also includes tools that are used for turning off Windows defender and legitimate sdel binaries. ..

    Mimic ransomware possesses a plethora of capabilities, including the following:

    Collecting system information
    Creating persistence via the RUN key
    Bypassing User Account Control (UAC)
    Disabling Windows Defender
    Disabling Windows telemetry
    Activating anti-shutdown measures
    Activating anti-kill measures
    Unmounting Virtual Drives
    Terminating processes and services
    Disabling sleep mode and shutdown of the system
    Removing indicators
    Inhibiting System Recovery…

    * Everything is my only search tool.

    3 users thanked author for this post.
    Viewing 1 reply thread
    Author
    Replies
    • #2529522

      I have Everything Toolbar v 0.7.1 on my system, it is in C:\Program Files (x86)\EverythingToolbar\, and has the file everything64.dll dated 3/29/2021. Thanks for the heads’ up, I have a note not to update it. I also have Everything Search Engine v1.4.1.1018 in C:\Program Files\Everything and that has no .dll files.

    • #2529658

      I have Everything Toolbar v 0.7.1 on my system, it is in C:\Program Files (x86)\EverythingToolbar\, and has the file everything64.dll dated 3/29/2021. Thanks for the heads’ up, I have a note not to update it. I also have Everything Search Engine v1.4.1.1018 in C:\Program Files\Everything and that has no .dll files.

      I use Portable Everything (latest Version 1.4.1.1022 (x64))
      I don’t (usually) install software.

    Viewing 1 reply thread
    Reply To: New Mimic Ransomware Abuses Everything APIs for its Encryption Process

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: