Uptime Hamster: 16d 22h 52mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ELPACO-team

ELPACO-team

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Ver en IntelTracker → APTTrail →
ELPACO-team is a financially motivated ransomware group that emerged in mid-2024 as a new variant of the MIMIC ransomware family. The group's primary objective is monetary gain through the encryption of victim files and the subsequent demand for cryptocurrency ransoms for decryption. A distinguishing characteristic of ELPACO-team is its tactical use of legitimate system tools, such as the 'Everything' file search utility, to efficiently locate and encrypt data while simultaneously disabling security defenses and establishing persistence. The group has been observed exploiting critical vulnerabilities, including CVE-2023-22527 in Atlassian Confluence, as a primary initial access vector in its operations. ELPACO-team operates under its own name, derived from the file extension it appends to encrypted files, and is understood to be a direct evolution within the broader MIMIC ransomware ecosystem.

Actores similares

auditteamactor · 16malwrhunterteamactor · 11audit-teamactor · 2AuditTeamactor · 2aztroteamransomware · 2fsteamransomware · 2malekteamransomware · 2teamxxxransomware · 2apt-1877teamactor · 1apt-hackingteamactor · 1
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
32
Actualizado
Fri, 19 Ju

Paises objetivo (SOCRadar)

AustraliaCanadaGermanyFranceUnited KingdomKorea, Republic ofNetherlandsRomaniaRussian FederationUnited States

Sectores objetivo (SOCRadar)

Energy & Utilities ConstructionManufacturingInformation ServicesFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOther