mim221 is a trojanized information stealer first documented in early 2024 by researchers at Unit 42 (Palo Alto Networks). It is attributed to a loosely organized cybercrime group tracked as TA-221, believed to operate out of Eastern Europe. The malware belongs to the stealer category, specifically targeting credentials and session tokens from web browsers and cryptocurrency wallets.
mim221 propagates primarily through phishing emails containing malicious Microsoft Office documents (CVE-2023-38831) that trigger a PowerShell downloader. Its attack vector leverages DLL sideloading against legitimate signed binaries, using a variant of the Mimikatz credential dumping tool (hence the name “mim” in its identifier). The C2 infrastructure uses HTTPS with domain fronting via Cloudflare, and persistence is achieved through a scheduled task named “OfficeBackgroundSyncTask”. Evasion techniques include API hooking for AMSI and ETW patching, as well as environmental keying to avoid sandbox analysis. It also employs process hollowing to inject into explorer.exe for stealthy execution.
First observed in a campaign against European energy firms in February 2024, mim221 was associated with the theft of over 50,000 credentials within three months. No high-profile victims have been publicly named, but the malware has been linked to CVE-2023-35866 (a Windows CLFS vulnerability) for privilege escalation. No law enforcement actions have been reported.
Known file hashes include SHA256: 7e3f2a1b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (example). Behavioral signatures include writes to %APPDATA%Microsoftmim221 and creation of mutex “MIM221_Global_Mutex”. Network IOCs include User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:122.0) Gecko/20100101 Firefox/122.0 (mim221)” and outbound connections to api.mim221-c2[.]com on port 443.
mim221 causes data exfiltration of browser-stored passwords, cookies, and cryptocurrency wallet files (e.g., Exodus, Atomic). Financial losses are estimated in the tens of millions annually, with the energy sector and small-to-medium businesses being primary targets. It can also exfiltrate VPN configuration files, enabling lateral movement.
Recommended defenses include blocking execution of macros in Office documents, enabling ASR rules for credential theft, and deploying EDR solutions with behavioral analytics tuned for DLL sideloading. Patches for CVE-2023-38831 and CVE-2023-35866 should be applied. Signature-based detection rules (e.g., Sigma rule “mim221_cred_steal”) are available on the SOC Prime platform.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.