Egregor was a ransomware-as-a-service operation first observed in September 2020 and widely assessed as a successor to Maze, with substantial overlap in affiliates and strong technical similarities to Maze and Sekhmet. It rapidly became one of the most active big-game ransomware operations of late 2020, targeting large organizations across multiple regions and industries. Reported victims included enterprises in retail, transportation, staffing, technology, and gaming, and the operation was particularly associated with attacks on organizations in the United States. Egregor combined file encryption with pre-encryption data theft and public leak threats, making it a double-extortion actor. Affiliates commonly stole unencrypted corporate data before deploying the ransomware and used a public leak site to pressure victims that refused to negotiate or pay. The operation followed a revenue-sharing model in which affiliates received the majority of ransom proceeds and the core operators retained a smaller percentage. Egregor also used public shaming tactics and was notable for printing ransom notes through accessible printers on compromised networks, a relatively uncommon behavior among ransomware families. Intrusion chains associated with Egregor commonly began with initial access provided by other criminal malware ecosystems, especially QakBot/Qbot, and in some cases Zloader. Reporting also linked Egregor intrusions to phishing campaigns using malicious macro-enabled documents, with follow-on use of Cobalt Strike for reconnaissance, privilege escalation, lateral movement, and broader post-compromise activity. Operators and affiliates were observed using tools such as Advanced IP Scanner for internal reconnaissance and Rclone for data exfiltration. Egregor is associated with capabilities spanning initial access, reconnaissance, scanning, credential-enabled post-compromise operations, lateral movement, persistence, defense evasion, exfiltration, and extortion. The malware and its operators were reported to avoid some CIS and Eastern European language environments, consistent with patterns seen in other post-Soviet cybercrime operations. In February 2021, Ukrainian authorities, working with French and U.S. partners, conducted enforcement actions against individuals allegedly involved in Egregor operations and affiliate activity. The group’s leak site went offline around that time, indicating major disruption to the operation. Known aliases include Egregor ransomware gang and Egregor ransomware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Ransomware operations responsible for hundreds of attacks against high-profile targets worldwide, using an affiliate program and a leak blog to pressure victims.
Described as a successor to Maze that also uses double extortion in ransomware campaigns.
Mentioned only as an example of successful ransomware branding/RaaS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.