This week, our Malware Lab examined a machine already infected with a sample that, after extensive research, we discovered was a version 4.3 of Mimic Ransomware.
It is a rare family, but still manages to be very effective and unpredictable, as it implements many malicious techniques and offers support for the execution of customised commands defined at compile time.
Among its many features, we observed:
- support for disabling Windows Defender;
- the deletion of backup catalogues;
- disabling the automatic reset functionality using wbadmin.exe;
- the deletion of Windows event logs.
In this report, we look at the features and the file encryption algorithm that have not been publicly documented until now.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/