Egregor, also known as the Egregor ransomware gang or Egregor ransomware operation, was a financially motivated ransomware-as-a-service operation that emerged in September 2020. It targeted large organizations across multiple industries, including transportation, staffing, retail, and video games. Known victims included TransLink, Randstad, Crytek, Ubisoft, Cencosud, Kmart, and Barnes & Noble. Its affiliate network attracted participants from Maze as that operation wound down; this overlap does not establish that the two operations were identical. Egregor used double extortion: affiliates compromised corporate networks, stole unencrypted information, and deployed ransomware, while the operation threatened to publish stolen data on its dedicated leak site unless victims paid. Affiliates generally received approximately 70–80 percent of ransom proceeds, with the core operators retaining the remainder. Egregor partnered with QakBot distributors for initial access, and its affiliates also used Zloader. The operation used Advanced IP Scanner for network reconnaissance. A distinctive pressure tactic involved repeatedly printing ransom notes on accessible printers, including receipt printers. Its attacks exposed sensitive business and personal information and disrupted organizational IT services and payment systems. In February 2021, Ukrainian authorities, working with French and U.S. authorities, conducted arrests and raids against Ukrainian participants in the operation. The enforcement action significantly disrupted Egregor, and its victim-shaming blog went offline. Law enforcement attributed attacks against more than 150 companies and losses exceeding US$80 million to the operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Ransomware operations responsible for hundreds of attacks against high-profile targets worldwide, using an affiliate program and a leak blog to pressure victims.
Described as a successor to Maze that also uses double extortion in ransomware campaigns.
Mentioned only as an example of successful ransomware branding/RaaS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.