🚨Threat Campaign Alert - ELPACO-Team Ransomware: Russian and South Korean Enterprises Targeted with Sophisticated Attacks🚨
Summary: A sophisticated ransomware variant, ELPACO-Team, has been identified, which uses advanced evasion techniques to target Windows systems. The malware deploys a series of malicious tools and legitimate utilities to disable system defenses, encrypt files, and ensure persistence.
Threat Actor/Threat Group: ELPACO-team
Malware: ELPACO-team Ransomware
Targeted Countries: Russia, South Korea
Targeted Industries: Enterprises and Individuals
Targeted Applications/CVE: Not Mentioned
Impact: Data encryption, system compromise, ransomware attack, and potential data loss.
IOC:
MD5
33eeeb25f834e0b180f960ecb9518ea0,
B93EB0A48C91A53BDA6A1A074A4B431E,
B951E50264F9C5244592DFB0A859EC41,
AC34BA84A5054CD701EFAD5DD14645C9,
0BF7C0D8E3E02A6B879EFAB5DEAB013C,
C44487CE1827CE26AC4699432D15B42A,
742C2400F2DE964D0CCE4A8DABADD708,
51014C0C06ACDD80F9AE4469E7D30A9E,
3B03324537327811BBBAFF4AAFA4D75B,
245FB739C4CB3C944C11EF43CDDD8D57,
1B37DC212E98A04576AAC40D7CE7D06A,
26F59BB93F02D5A65538981BBC2DA9CC,
03A63C096B9757439264B57E4FDF49D1,
57850A4490A6AFD1EF682EB93EA45E65,
FADE75EDBF62291FBB99C937AFC9792C,
B951E50264F9C5244592DFB0A859EC41,
803DF907D936E08FBBD06020C411BE93,
MITRE TTP IDs:
T1566 (Phishing),T1190 (Exploit Public-Facing Application),T1059 (User Execution),T1203 (Exploitation for Client Execution),T1204.002 (Malicious File),T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder),T1070.004 (Indicator Removal: File Deletion),T1082 (System Information Discovery),T1083 (File & Directory Discovery),T1016 (System Network Configuration Discovery),T1005 (Data from Local System),T1486 (Data Encrypted for Impact)
Reference: This writing is based on Research Advisory Report published by ‘Cyfirma' Team.
------------------------------------------------------------------------------------------
🚀Join us on our mission to secure the digital world and make cyber defense affordable to everyone! 🌐 Follow "CyberXTron Technologies" for the timely, relevant and actionable cyber threat insights.
#ELPACOTeam #Ransomware #MimicRansomware #RaaS #CyberThreat #DataBreach #DeviceCompromise #Malware #ThreatIntelligence #cyberXTron #uncovertheunknown🛡️🔒