Malicious Ransomware Extension Class Registration for ELPACO-team by Elpaco Ransomware

PremiumReviewedSigma · Critical · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-08-01
Updated
2026-08-28

ATT&CK techniques

Persistence → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule detects registration of the .ELPACO-team file extension class under HKLM Classes. Elpaco ransomware, a Mimic variant, registers its own encrypted-file extension to associate the ransom note handler after encryption. Presence of this class key indicates ransomware has executed and modified file associations on the host.

Related detections9 linkedT1112 — drag to rearrange
Possible Akira Ransomware Note or Encrypted Extension Creation
Malicious Storm-2603 Ransom Note File Creation
Possible Ransomware Note or Encrypted File Extension Creation
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious Gh0stBins RAT Registry Marker HHClient
Suspicious PebbleDash C2 Configuration Stored Under WMI Security Key (via registry_set)
Suspicious WDigest UseLogonCredential Enablement for Plaintext Credential Theft (via registry_set)
PowerShell Storing an Encoded Payload in the Registry (via process_creation)
BitLocker Feature Activation on Multiple Hosts - Native (via bitlocker)
Malicious Ransomware Extension Class Registration for ELPACO-team by Elpaco Ransomware
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.