Sekhmet is a ransomware family that emerged in March 2020 and targeted corporate networks. It is associated with double-extortion activity, including operation of a leak site referred to as "Leaks leaks and leaks," and is also listed among ransomware groups that published stolen victim data through dedicated leak portals. Multiple reports in the provided content link Sekhmet closely with Maze and Egregor: Egregor is described as an offshoot or relative of Sekhmet, and several sources state that Egregor, Maze, and Sekhmet are believed to derive from the same underlying software. Supporting overlap cited in the content includes similarities in code, behavior, ransom notes, configuration format, obfuscation style, payment-site naming, and even decryptors labeled "Sekhmet Decryptor" being sent to some Egregor victims. The content does not provide a standalone technical profile for Sekhmet’s encryption routine or initial access vectors, but it does high-confidence associate Sekhmet with enterprise-focused ransomware operations, data theft and leak-site extortion, and close lineage or shared tooling with the Maze/Egregor cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the malware family from which Egregor is derived, with noted similarities in configuration format and obfuscation style.
Ransomware family believed to be created from the same software/codebase as Maze and Egregor.
Ransomware described as sharing underlying software/code and operational artifacts with Maze and Egregor; name appears in decryptor title ('Sekhmet Decryptor') sent to some Egregor-paying victims.
Ransomware targeting corporate networks with explicit data-theft threats and a leak site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.