Egregor emerged as a ransomware-as-a-service operation tied to the Sekhmet/Maze lineage and rapidly targeted organizations worldwide, including at least 69 victims observed by France’s ANSSI, with some ransom demands exceeding $4 million. The group encrypted files with randomized extensions, dropped the ransom note RECOVER-FILES.txt, and threatened to publish stolen data within three days if victims did not negotiate through Tor-based payment and chat portals. Researchers linked Egregor to former Maze affiliates based on code overlap, shared infrastructure, similar ransom notes, and the migration of operators after Maze’s shutdown.
Intrusions commonly began with phishing or illicit RDP access and frequently involved Qakbot, IcedID, Ursnif, Cobalt Strike, AdFind, SharpHound, PsExec, and RClone for reconnaissance, lateral movement, and exfiltration before encryption. Technical analyses described obfuscated DLL payloads, process injection, defense evasion, shadow-copy deletion, and file encryption using ChaCha with RSA-2048, while the malware avoided systems configured for several CIS-region languages. Egregor was linked to attacks on organizations including GEFCO, Barnes & Noble, and Ubisoft, and operated a public leak site—described by some researchers as a “Hall of Shame”—to pressure non-paying victims.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
In February 2021, alleged Egregor operators were arrested in Ukraine during a joint French-Ukrainian investigation coordinated by Europol. Around the same time, Egregor’s extortion site went offline.
On 6 January 2021, the FBI issued a Private Industry Notification, coordinated with DHS-CISA, warning that Egregor was targeting businesses worldwide. The notice described the group’s double-extortion tactics, ransomware-as-a-service model, common intrusion and post-compromise tools, and recommended mitigations.
As of November 24, 2020, the Egregor leak site listed 152 companies across multiple industries and geographies. The most represented sectors were Information Technology and Services, Construction, Retail, Consumer Goods, and Automotive.
ANSSI reported observing a large Egregor campaign since mid-September 2020, with at least 69 organizations targeted, including French companies. The report said ransom demands could exceed $4 million and linked the operation to former Maze affiliates and the Sekhmet family.
The Sekhmet profile states that decryption keys were publicly released in February 2022 and that Emsisoft published a decryptor for Maze, Sekhmet, and Egregor victims. This marked a post-campaign recovery development for affected organizations.
A 29 October 2020 update stated that Maze operators shut down the Maze ransomware project and moved to Egregor. The same source says the operators later confirmed Maze, Sekhmet, and Egregor were related ransomware programs.
Multiple sources state that Egregor activity began in mid-September 2020, marking the emergence of the ransomware-as-a-service operation. It used double extortion, encrypting systems after stealing data and threatening publication if victims did not respond.
An update dated 24 March 2020 said Sekhmet operators created the "Leaks leaks and leaks" site to publish stolen data from companies that refused to pay. The article notes that before this, publication had only been threatened.
The Sekhmet ransomware operation was reported as active and peaking around mid-March 2020, targeting business users with encryption and data-theft extortion. The article places Sekhmet in the Maze-to-Sekhmet-to-Egregor lineage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcegroup-ib.com
Open sourcelabs.sentinelone.com
Open sourcecert.ssi.gouv.fr
Open sourceblog.minerva-labs.com
Open sourcecert.ssi.gouv.fr
Open sourcecert.ssi.gouv.fr
Open sourceassets.documentcloud.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.