Egregor was a financially motivated ransomware-as-a-service (RaaS) operation active from September 2020 through its significant disruption in February 2021. It targeted large organizations globally, with substantial activity against U.S.-based entities. The operation used affiliate partners to obtain corporate-network access, conduct reconnaissance, escalate privileges, move laterally, exfiltrate data, and deploy ransomware. Affiliates reportedly retained approximately 70–80% of ransom proceeds, with the core operation receiving the remainder. Egregor employed double extortion: it stole victim data before encryption and threatened public disclosure through its leak site if victims did not pay or engage. It commonly required victims to contact the operators within 72 hours. The malware used ChaCha and RSA cryptography and incorporated obfuscation and language-based execution exclusions. A notable operational tactic was printing ransom demands on accessible network printers. Observed intrusion chains included phishing documents delivering QakBot, IcedID, or Ursnif, followed by Cobalt Strike for post-compromise activity and Rclone for data exfiltration. Egregor affiliates also partnered with QakBot distributors for initial access and have been associated with use of Advanced IP Scanner for internal reconnaissance. Known victims included Ubisoft, Barnes & Noble, Crytek, Randstad, and TransLink, with impacts spanning technology, retail, staffing, transportation, and public-sector organizations. Egregor is widely assessed as operationally and technically linked to Maze and Sekhmet. Maze affiliates were widely reported to have migrated to Egregor following Maze's shutdown, and the ransomware families shared closely related code. In February 2021, Ukrainian authorities, working with French, U.S., and Europol partners, took action against alleged Egregor operators and affiliates. The operation's leak site went offline around that time, materially disrupting its activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Ransomware operations responsible for hundreds of attacks against high-profile targets worldwide, using an affiliate program and a leak blog to pressure victims.
Described as a successor to Maze that also uses double extortion in ransomware campaigns.
Mentioned only as an example of successful ransomware branding/RaaS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.