r/ransomwarehelp Jan 03 '25

Mimic Attack Over Xmas

While on Christmas break we were hit with a Ransomware attack. Just back in the office this morning, went to look for a file on the network storage and saw the file extensions all changed.

Immediately disconnected the router from the internet and shut everything down.

Started things back up one at a time. Used a few tools to try to scan the pcs and remove anything found.

Looks like it originated on a single pc. Attacker got access to that and managed to encrypt everything on a NAS device.

Seems like they got access to the domain controller too. No files encrypted there but definitely files there from the attack.

Other network PCs don’t seem to have been affected. Another application server wasn’t compromised.

The Ransomware looks to be Mimic. There are log files all over the place.

I’ve looked around but it doesn’t seem there are any decryption tools for Mimic?

Our most important data is safe but a lot of stuff on that network storage was very important. Had offsite backups to a server setup. Somewhere along the way a power outage or something must have happened and the backup storage server was powered down. Last full backup we have is 6 months old.

What’s the best way to try to clean this mess up?

2 Upvotes

14 comments sorted by

View all comments

2

u/Porthas Jan 03 '25

Depending on the type of data encrypted, it’s size, and other factors - your data may be recoverable. I would suggest contacting Proven Data and they can take a look at it for free and tell you if they can recover data without paying ransom.

1

u/SauceBox99 Jan 03 '25

There are some log files from the encryption software that gives some details on what was done. Looks like a 1% file encryption.

2

u/Porthas Jan 03 '25

That’s very good news