Ukrainian, French, and U.S. authorities disrupted the Egregor ransomware operation through coordinated raids in Ukraine that led to the arrest of three suspected members and targeted alleged ring leaders and affiliate associates. Investigators linked the case to attacks on French organizations including Ubisoft, Gefco, and Ouest France, while Ukrainian officials said Egregor had struck more than 150 companies and caused losses exceeding $80 million. After the operation, Egregor’s leak site went offline, indicating a major blow to the group, which researchers and investigators have also tied to the former Maze ransomware ecosystem.
In a parallel international action, the U.S. Department of Justice announced a global disruption of NetWalker, another ransomware-as-a-service operation, charging Canadian national Sebastien Vachon-Desjardins, seizing about $454,530 in cryptocurrency, and taking down a dark web site used to communicate with victims. The DOJ said NetWalker hit healthcare providers, municipalities, schools, universities, law enforcement, and emergency services, with healthcare organizations particularly targeted during the COVID-19 pandemic. French investigators said ransomware cases remain difficult because attackers move faster than judicial processes, forcing police to rely on infrastructure mapping, indicators of compromise, and private-sector intelligence to identify operators and support cross-border takedowns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On February 9, 2021, Ukrainian law enforcement, working with U.S. and French authorities, conducted an operation against several Ukrainian nationals allegedly involved in Egregor ransomware. The action targeted suspected ring leaders and associates connected to Egregor’s affiliate programs.
The U.S. Department of Justice announced a coordinated international operation against NetWalker that included charges against Sebastien Vachon-Desjardins and the seizure of a dark web hidden service used to communicate with victims. Bulgarian authorities assisted in the hidden service seizure, and the FBI Tampa Field Office led the investigation.
Law enforcement seized approximately $454,530.19 in cryptocurrency on Jan. 10 as part of the NetWalker investigation. The funds were described as ransom payments from three separate NetWalker attacks.
Maze announced in late 2020 that it was shutting down operations. Threat intelligence professionals widely believed many Maze affiliates later moved to Egregor.
Following the February 2021 law enforcement action, Egregor’s leak blog was taken offline. The disruption was cited as evidence that the raids significantly impacted the ransomware operation.
French and Ukrainian authorities arrested three suspected members of the Egregor ransomware operation in Ukraine. French police said one suspect appeared deeply involved with the main actor, while two others provided support including privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourcetherecord.media
Open sourcejustice.gov
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.