Overview
Platforms:
Windows
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
—
Top countries:
—
Observed sectors:
—
Attribution
Maze-linked operators
PROBABLE
Suspected successor relationship
Multiple researchers assessed Egregor as a likely successor to Maze and observed operational continuity between the two ecosystems, but identical core ownership has not been conclusively established.
Affiliates
No affiliate information available.
Activity
Recent Observations
Egregor operation disrupted
February 2021
Law-enforcement action
French and Ukrainian authorities targeted individuals associated with Egregor, while supporting infrastructure went offline and sustained activity ceased.
Crytek ransomware attack
October 2020
Major incident
Crytek later confirmed that Egregor ransomware encrypted systems and that stolen information was published through the operation's leak infrastructure.
Egregor operation emerges
September 2020
Ransomware activity
Egregor emerged as a ransomware-as-a-service operation during the decline of Maze and rapidly expanded through affiliate-driven attacks.
TTPs
ATT&CK coverage:
6 techniques
· 5 tactics
T1197
BITS Jobs
VERIFIEDDefense Evasion / Persistence
Egregor used BITSAdmin to download and execute malicious DLL payloads.
T1059.001
PowerShell
VERIFIEDExecution
Egregor used encoded PowerShell commands during post-compromise activity and lateral movement.
T1484.001
Group Policy Modification
VERIFIEDDefense Evasion / Privilege Escalation
Egregor was capable of modifying Group Policy settings to evade detection.
Show more TTPs (3)
T1055
Process Injection
VERIFIEDDefense Evasion / Privilege Escalation
Egregor could inject its payload into Internet Explorer processes.
T1071.001
Web Protocols
VERIFIEDCommand and Control
Egregor communicated with command-and-control infrastructure over HTTPS.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Egregor encrypted non-system files using a hybrid AES-RSA encryption scheme before displaying a ransom note.
Victims
Crytek
CONFIRMED
Technology organization in Germany.
CVEs
No CVE associations available.
Infrastructure
Egregor leak site
Egregor operated leak infrastructure used to publish stolen victim information as part of its double-extortion model.
Egregor C2 infrastructure
Egregor communicated with command-and-control servers over HTTPS and could transfer collected victim data through its C2 channel.
Timeline
2021-02
Law-enforcement disruption
French and Ukrainian authorities targeted participants associated with Egregor, followed by the disappearance of the operation's infrastructure and sustained activity.
2020-10
Rapid expansion
Egregor rapidly expanded its victim base and became a prominent big-game hunting and double-extortion operation.
2020-10
Crytek attack
Crytek was compromised by Egregor ransomware, with systems encrypted and stolen information later published.
Show more events (1)
2020-09
Egregor first observed
Egregor emerged as a ransomware-as-a-service operation during the decline of Maze.
Sources
The Egregor Ransomware
CERT-FR / ANSSI
Show more sources (3)
Common Situational Picture 2021
French National Cybersecurity Agency / ANSSI