mimic-guram

First seen
2023-04-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:55:47

Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical government-and-public-sector manufacturing energy-and-utilities

Context

Mimic v.10 Ransomware-as-a-Service (RaaS). The malware is designed to target various operating systems (Windows, ESXi, NAS, FreeBSD) and features network-wide deployment, file obfuscation, backup destruction, UAC bypass, and multithreaded encryption. The service offers additional tools like NTLM password decryption and call-based extortion. They prohibit attacks on CIS countries and require active participation, with decryption tools available for a fee currently 800USD.

Reports & references

  • ransomlook.io — Mimic Guram (report)

External references