Skip to main content
Mallory
MalwareRansomwareUsed by 2 actors

Everest

Also known asEverest Ransomware

Everest is a Russia-linked ransomware-as-a-service (RaaS) operation active since at least 2020. It is consistently described as a double-extortion group: operators exfiltrate data, encrypt systems, and threaten to leak or sell stolen information if victims do not pay. The reporting also states that Everest has expanded into initial access brokerage, including selling network footholds to other threat actors.

The group has been publicly associated with numerous victim claims across sectors and geographies, including finance, healthcare, aviation, energy, manufacturing, retail, and technology. Reported or claimed victims in the provided content include Frost Bank, Citizens Financial Group, Under Armour, Petrobras, Dublin Airport, Iberia, Vikor Scientific/Vanta Diagnostics via third-party provider Catalyst RCM, Polycom/HP Poly-linked systems, Hosokawa Micron Corporation, and others. In healthcare-related reporting, Everest claimed theft of internal documents, EMRs, patient information, billing data, and PDF databases from Vikor Scientific and affiliated labs; the related incident was reported as affecting 139,964 individuals. In financial-sector reporting, Everest claimed large datasets from Frost Bank and Citizens, though both organizations stated the exposure originated from a third-party vendor and said they had no evidence of unauthorized access to their own internal networks.

Everest operates a Tor-based leak site and uses timed publication deadlines as part of extortion. Examples in the content include six-day, seven-day, eight-day, and nine-day countdowns before alleged public release. The group has claimed theft volumes such as 343 GB in the Under Armour case, approximately 90 GB in the Polycom-linked case, and 159 GB in the SIAD Group claim. In some cases, screenshots or sample data were posted to support claims, although multiple reports note that some allegations were unverified or lacked independent confirmation.

Behavior and tradecraft directly mentioned in the content include data theft prior to encryption, public leak-site shaming, and in at least one victim report, advice to monitor for lateral movement and Cobalt Strike-related activity following an Everest compromise. The content also notes that the same defacement message later seen in the May 2025 LockBit panel compromise had previously been used in a compromise of Everest’s dark web leak site, indicating Everest itself was at one point targeted by an unknown actor.

Targeting reflected in the provided material spans the United States, Europe, Japan, South Korea, and Brazil, with impacts or claims involving banks, airlines and airports, diagnostic and laboratory services, industrial firms, and major consumer brands. Only high-confidence details from the supplied content indicate Everest is best characterized as an active, high-volume double-extortion ransomware operation with broad sector targeting, leak-site-based coercion, and occasional overlap with third-party/supply-chain compromise scenarios.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Everest

"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."

via ncc group researchnccgroup.com
Black-Byte

"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."

via ncc group researchnccgroup.com
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1078Valid AccountsEvidence1

"an authorized login was misused to access a server on November 8–9, 2025, and copy data without permission."

Persistence

1 technique
T1078Valid AccountsEvidence1

"an authorized login was misused to access a server on November 8–9, 2025, and copy data without permission."

T1078Valid AccountsEvidence1

"an authorized login was misused to access a server on November 8–9, 2025, and copy data without permission."

Stealth

1 technique
T1078Valid AccountsEvidence1

"an authorized login was misused to access a server on November 8–9, 2025, and copy data without permission."

Collection

1 technique
T1213Data from Information RepositoriesEvidence1

"access a server on November 8–9, 2025, and copy data without permission."

Exfiltration

5 techniques
T1020Automated ExfiltrationEvidence1

"The group alleges it obtained approximately 90GB of internal data... the data is described as a database and internal company documentation."

T1048.003Exfiltration Over Unencrypted Non-C2 ProtocolEvidence1

"Everest Ransomware Says It Breached Brazilian Energy Giant Petrobras" / "demanding contact through qTox"

T1537Transfer Data to Cloud AccountEvidence1

"The images appear to show internal file directories, engineering build environments, source code trees, software logs, and technical documentation linked to Polycom’s conferencing platforms..."

T1567Exfiltration Over Web ServiceEvidence2

The Everest ransomware gang listed Frost Bank and Citizens Financial Group on its dark web leak site on April 20th, setting a six-day deadline before publicly releasing stolen data.

T1567.002Exfiltration to Cloud StorageEvidence1

"publicly disclosed the victims on their Dedicated Leak Sites (DLS)"

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence4
TacticImpact

The Everest ransomware-as-a-service (RaaS) operation has been active since at least 2020, running a double-extortion model. This means the Russia-linked attackers steal data, encrypt systems, and threaten to publish everything if the victim doesn't pay.

T1657Financial TheftEvidence1
TacticImpact

The attackers released samples of sensitive financial data, setting a six-day ultimatum before public release... This is a very common extortion tactic used by ransomware gangs to pressure victims into negotiating and eventually paying the ransom.

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app4 years ago
ip.v4●●●●●●●●●●●●View more in app4 years ago
ip.v4●●●●●●●●●●●●View more in app4 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.