Sekhmet is a Windows ransomware family first observed in March 2020 and closely associated with the Maze and Egregor ransomware lineage. Multiple analyses describe Sekhmet as nearly identical to Maze aside from minor implementation differences such as file-marker handling, while Egregor is widely characterized as a direct variant or offshoot of Sekhmet. The family was active during the rise of double-extortion ransomware operations and is linked to leak-site based coercion in which operators not only encrypted victim files but also stole unencrypted data and threatened public disclosure if victims refused to negotiate or pay.
Sekhmet encrypts files and appends a random extension. Reporting and ransom-note analysis tie the family to ChaCha-based file encryption, and operationally it follows the same extortion model seen in Maze and later Egregor. Victims were instructed to contact the operators through dedicated negotiation infrastructure, and the operation maintained a public leak site used to pressure non-paying organizations. Sekhmet has also been identified among ransomware groups that escalated pressure by calling victims directly during negotiations.
The malware targeted enterprise environments rather than commodity consumer infections and fits the broader big-game-hunting trend of 2020. It is associated with theft of sensitive corporate data prior to encryption, public shaming or leak threats, and conventional ransomware impact on business operations. The family is notable historically because it sits between Maze and Egregor in both code lineage and operational evolution, and because later public release of master decryption keys enabled free decryption for some victims when paired with the required ransom-note material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Этот крипто-вымогатель шифрует данные бизнес-пользователей и компаний с помощью RSA-2048 + ChaCha, а затем требует выкуп... Вымогатели, распространяющие Sekhmet, угрожают опубликовать украденные данные с целью усиления давления на жертву.
Both Egregor and Maze, as well as Sekhmet, were attributed to the same group of organized cybercriminals tracked altogether as the TwistedSpider cryptonym by CrowdStrike.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Как известно из других Ransomware, для этого операторы-вымогатели начинают кражу данных ещё перед шифрованием файлов... We downloaded confidential and private data.
the tactics used by ransomware gangs to put pressure on victims to pay ransom demands after they've encrypted corporate networks.
Вымогатели, распространяющие Sekhmet, угрожают опубликовать украденные данные с целью усиления давления на жертву... Your company network has been hacked and breached. We downloaded confidential and private data. In case of not contacting us in 3 business days this data will be published on a special website available for public view.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another ransomware family associated with encryption plus data extortion.
Ransomware family from which Egregor is derived; its operators also published victim data on a leak site.
Ransomware referenced as the base variant for Egregor.
Ransomware family that encrypts files with a random extension and requires the ransom note file for decryption with this utility.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.