Everest is a Russian-speaking, Russia-linked ransomware and data-extortion operation active since at least late 2020. It has used double extortion, combining data theft and file encryption with threats to publish stolen information, and later expanded its activity toward encryptionless data extortion and initial-access brokerage. Everest has also advertised stolen remote-access credentials and sought corporate insiders who could provide access to enterprise networks. The operation has targeted organizations across North America, Europe, and Asia, including government, healthcare, telecommunications, financial-services, manufacturing, and transportation entities.
Everest intrusions have been associated with exploitation of vulnerable public-facing applications, phishing, and stolen credentials. Its Windows encryptor is a protected .NET payload that terminates security and analysis processes, disables selected endpoint protections, deletes shadow copies, disrupts backup recovery, and uses locale-based geofencing to avoid systems configured for Commonwealth of Independent States regions. It can use Wake-on-LAN to bring sleeping devices online for encryption, encrypts files using symmetric encryption with asymmetric key protection, partially encrypts large files to accelerate execution, and removes itself after completion. Data theft, where performed, may occur through tooling separate from the encryptor. Everest’s relationships to other ransomware operations are not conclusively established, although a code connection to BlackByte has been documented.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."
"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Everest has operated as an initial access broker since November 2021, selling stolen VPN and RDP credentials to other criminal operators.
The encryptor itself is a .NET executable protected with ConfuserEx, a tool that strips identifying watermarks and adds anti tampering layers before analysis begins.
From there, the malware disables Windows Defender’s Controlled Folder Access, deletes shadow copies, wipes backup related files... The ransomware wraps up by dropping a note called EVERESTRANSOMWARE.txt into every affected folder and on the desktop, before triggering a delayed self deletion routine to erase its own tracks.
One of the more unusual traits AttackIQ flagged is the ransomware’s use of Wake on LAN broadcasts, sent to force sleeping machines on the network to power up so they too can be encrypted.
Known IOCs associated with Everest include SoftPerfect Network Scanner and ProcDump for credential dumping and reconnaissance. Play uses AdFind, a command-line Active Directory query tool used for network discovery.
"The group alleges it obtained approximately 90GB of internal data... the data is described as a database and internal company documentation."
"Everest Ransomware Says It Breached Brazilian Energy Giant Petrobras" / "demanding contact through qTox"
Despite boasting about stealing a full terabyte of data from a victim organization, the actual malware sample used in the intrusion contains no code capable of exfiltrating anything at all.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the ransomware operation claiming a later Stadler Rail attack; no further operational details are provided.
A hybrid extortion operation that has used AES/DES Windows ransomware with a .everest extension, while increasingly emphasizing data theft, access brokering, and insider recruitment.
Everest is identified as the ransomware group responsible for the reported attack against GGS.
Everest is identified as the ransomware group responsible for the reported attack against Rise UP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.