Everest is a Russian-speaking cybercriminal extortion and ransomware group active since late 2020. The group is widely tracked as Everest or the Everest ransomware gang. It initially operated as a conventional ransomware actor but later shifted much of its activity toward data theft and encryption-less extortion, threatening to leak or sell stolen information rather than relying primarily on network-wide encryption. Everest has also been reported to function as an initial access broker, including reselling compromised access and credentials to other criminals, and has sought insider-enabled access to victim environments. Everest targets organizations across multiple sectors and geographies, with repeated victim reporting involving the United States and Europe. Confirmed victim sectors include information technology, health care, financial services, transportation, and industrial/manufacturing-related organizations. Reported operations have included compromises through third-party and supplier relationships, such as accessing shared platforms with compromised supplier credentials, as well as broader extortion campaigns against large enterprises and critical-infrastructure-adjacent organizations. The group’s tradecraft is associated with credential abuse for initial access, data exfiltration, extortion demands, and post-compromise monetization of stolen access. Everest has been described as evolving from ransomware encryption to data-theft extortion, while still being referred to as a ransomware gang in public reporting. It has also been linked to double-extortion activity and leak-site operations used to pressure victims. Public reporting further indicates that Everest has at times used data obtained by other threat actors in its own extortion schemes. Known aliases include everest_group, everest_ransomware, everest_ransomware_actors, everest_ransomware_gang, everest_ransomware_group, everest_ransomware_team, and everest_team.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Keysight.
Ransomware/extortion group tied to a July 2026 attack on Stadler Rail. In this incident, the group allegedly used compromised supplier credentials to access a shared data-exchange platform, stole technical data, and demanded 10 million Swiss francs. The content says the group originally used encrypting ransomware but later shifted to data theft and extortion without encrypting victim systems.
Conducting extortion following a breach of a supplier-linked data exchange platform; described as having evolved from data-theft-only operations into a hybrid ransomware and initial access broker operation, including selling stolen credentials and recruiting insiders for network access.
Financially motivated extortion group that steals data and threatens to publish or sell it rather than typically encrypting victim systems. In this incident, it allegedly used compromised login credentials to access a shared data exchange platform and extort Stadler Rail.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.