Sekhmet was a ransomware operation launched in March 2020 and is widely assessed as part of the same criminal ecosystem as Maze and Egregor. Multiple analyses have found that Sekhmet, Maze, and Egregor share nearly identical base code, core features, and obfuscation approaches, and Sekhmet has been described as a rebranding or closely related branch used to evade law-enforcement pressure. CrowdStrike has tracked Maze, Egregor, and Sekhmet together under the TwistedSpider cryptonym. Sekhmet was associated with the modern double-extortion ransomware model in which operators steal victim data before or alongside encryption and then threaten public release through a leak site to coerce payment. Sekhmet was among the ransomware operations known for maintaining a data-leak platform and using stolen unencrypted files for extortion. The operation is also linked to the broader evolution of cartel-style ransomware cooperation around the Maze ecosystem, although the precise organizational boundaries between Maze, Sekhmet, and Egregor were often blurred. Technical reporting consistently places Sekhmet in the same lineage as Maze and Egregor, with differences described mainly as minor implementation changes such as file markers and ransom-note text rather than major architectural divergence. Publicly leaked master decryption keys released in 2022 were validated as legitimate for Maze, Egregor, and Sekhmet, further reinforcing their close relationship and enabling free decryption for victims. Sekhmet should be understood as a financially motivated cybercriminal ransomware brand within the Maze/Egregor lineage rather than a distinct nation-state actor. Known related names and aliases in reporting include Maze, Egregor, and the broader cluster designation TwistedSpider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a rebranded successor/variant associated with Maze in order to evade law enforcement.
Ransomware operation launched in March 2020; the content notes similarities with Egregor and Maze, including similar core features and obfuscation.
Referenced as a closely related ransomware variant/group sharing near-identical code with Egregor and Maze.
Mentioned as a ransomware group/family whose code and obfuscation techniques resemble Egregor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.