In a recent incident response case, Kaspersky dealt with a variant of the Mimic ransomware with some interesting customization features.
The attackers were able to connect via RDP to the victim’s server after a successful brute force attack and then launch the ransomware. After that, the adversary was able to elevate their privileges by exploiting the CVE-2020-1472 vulnerability (Zerologon). The identified variant abuses the Everything library and provides an easy-to-use GUI for the attacker to customize the operations performed by the malware. It also has features for disabling security mechanisms and running system commands. This ransomware variant is named “Elpaco” and contains files with extensions under the same name. In this post, Kaspersky researchers provide details about Elpaco, besides already shared, as well the tactics, techniques and procedures (TTPs) employed by the attackers.
Read more…
Source: Kaspersky
Related:
- CareCloud confirms 3.7M patients had their medical records stolen in data breach
August 19, 2026
Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health ...
- Defending against an active threat to Siemens S7 Series PLCs
August 19, 2026
This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as ...
- ‘Proactive SIM’ cards can hijack smartphones, IoT devices and even EV chargers
August 18, 2026
A malicious SIM card can instruct the device it sits in to run commands of an attacker’s choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the entire device over. Researchers from the University of Birmingham and the German security firm Fuzzware demonstrated ...
- Mitigating large-scale credential attacks
August 18, 2026
Identity has effectively become the new perimeter, where cybercriminals are increasingly choosing to log in rather than break in. To accomplish this, attackers frequently gather previously leaked username and password pairs. Gathering these credentials can then allow them to pivot to password spraying against services exposed to the internet, gaining credentials for other products and ...
- Hunting MacSync Stealer infrastructure through behavioral pivots
August 18, 2026
MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure. Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors ...
- ‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
August 17, 2026
An unprecedented number of Apple customers have reported receiving a recent threat notification alerting them to suspected spyware attacks targeting their devices, according to experts who investigate these types of incidents. Several people publicly and privately reported receiving Apple’s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in ...

