The Egregor ransomware operation carried out double-extortion attacks by stealing sensitive data, encrypting victim systems, and threatening to publish stolen information on a leak site if victims refused to pay. Researchers linked Egregor to an ecosystem associated with Sekhmet and possible former Maze affiliates, with additional reported ties to ProLock and LockBit. Victims cited in reporting included GEFCO, Barnes & Noble, and Ubisoft, while the group’s leak site reportedly listed 152 victim companies across industries including information technology, construction, retail, consumer goods, and automotive.
Intrusions commonly began with phishing or RDP exploitation, after which attackers used Cobalt Strike for payload delivery and in some cases leveraged QBot and living-off-the-land tools such as bitsadmin. The malware used heavily obfuscated DLL payloads with Salsa20-encrypted configuration data, required a sample-specific launch key passed with the -p parameter, and encrypted files with ChaCha and RSA-2048. Researchers also observed the group using Rclone with attacker-supplied configuration data to exfiltrate stolen files, while the ransomware appeared to avoid encrypting systems configured with several CIS-region languages.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
The Egregor ransomware family was active starting in mid-September 2020. The group was described as an offshoot of Sekhmet and linked by multiple security firms to former Maze affiliates, with possible ties to ProLock and LockBit.
As of 2020-11-24, Egregor's leak site reportedly listed 152 victim companies across multiple industries worldwide. Information technology, construction, retail, consumer goods, and automotive were the most frequently represented sectors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.