The Egregor ransomware operation carried out double-extortion attacks by stealing sensitive data, encrypting victim systems, and threatening to publish stolen information on a leak site if victims refused to pay. Researchers linked Egregor to an ecosystem associated with Sekhmet and possible former Maze affiliates, with additional reported ties to ProLock and LockBit. Victims cited in reporting included GEFCO, Barnes & Noble, and Ubisoft, while the group’s leak site reportedly listed 152 victim companies across industries including information technology, construction, retail, consumer goods, and automotive.
Intrusions commonly began with phishing or RDP exploitation, after which attackers used Cobalt Strike for payload delivery and in some cases leveraged QBot and living-off-the-land tools such as bitsadmin. The malware used heavily obfuscated DLL payloads with Salsa20-encrypted configuration data, required a sample-specific launch key passed with the -p parameter, and encrypted files with ChaCha and RSA-2048. Researchers also observed the group using Rclone with attacker-supplied configuration data to exfiltrate stolen files, while the ransomware appeared to avoid encrypting systems configured with several CIS-region languages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The Egregor ransomware family was active starting in mid-September 2020. The group was described as an offshoot of Sekhmet and linked by multiple security firms to former Maze affiliates, with possible ties to ProLock and LockBit.
As of 2020-11-24, Egregor's leak site reportedly listed 152 victim companies across multiple industries worldwide. Information technology, construction, retail, consumer goods, and automotive were the most frequently represented sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourcecve.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.