Overview

Platforms: Windows
Variants: —
Extensions: —
ATT&CK software: —
Initial access: —
Top countries: —
Observed sectors: —

Attribution

Maze-linked operators PROBABLE
Suspected successor relationship
Multiple researchers assessed Egregor as a likely successor to Maze and observed operational continuity between the two ecosystems, but identical core ownership has not been conclusively established.

Affiliates

No affiliate information available.

Activity

Recent Observations

Egregor operation disrupted
February 2021
Law-enforcement action
French and Ukrainian authorities targeted individuals associated with Egregor, while supporting infrastructure went offline and sustained activity ceased.
Crytek ransomware attack
October 2020
Major incident
Crytek later confirmed that Egregor ransomware encrypted systems and that stolen information was published through the operation's leak infrastructure.
Egregor operation emerges
September 2020
Ransomware activity
Egregor emerged as a ransomware-as-a-service operation during the decline of Maze and rapidly expanded through affiliate-driven attacks.

TTPs

ATT&CK coverage: 6 techniques · 5 tactics
T1197 BITS Jobs
VERIFIED
Defense Evasion / Persistence
Egregor used BITSAdmin to download and execute malicious DLL payloads.
T1059.001 PowerShell
VERIFIED
Execution
Egregor used encoded PowerShell commands during post-compromise activity and lateral movement.
T1484.001 Group Policy Modification
VERIFIED
Defense Evasion / Privilege Escalation
Egregor was capable of modifying Group Policy settings to evade detection.
Show more TTPs (3)
T1055 Process Injection
VERIFIED
Defense Evasion / Privilege Escalation
Egregor could inject its payload into Internet Explorer processes.
T1071.001 Web Protocols
VERIFIED
Command and Control
Egregor communicated with command-and-control infrastructure over HTTPS.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Egregor encrypted non-system files using a hybrid AES-RSA encryption scheme before displaying a ransom note.

Victims

Crytek CONFIRMED
October 2020 Germany Technology
Technology organization in Germany.

CVEs

No CVE associations available.

Infrastructure

Egregor leak site
Egregor operated leak infrastructure used to publish stolen victim information as part of its double-extortion model.
Egregor C2 infrastructure
Egregor communicated with command-and-control servers over HTTPS and could transfer collected victim data through its C2 channel.

Timeline

2021-02
Law-enforcement disruption
French and Ukrainian authorities targeted participants associated with Egregor, followed by the disappearance of the operation's infrastructure and sustained activity.
2020-10
Rapid expansion
Egregor rapidly expanded its victim base and became a prominent big-game hunting and double-extortion operation.
2020-10
Crytek attack
Crytek was compromised by Egregor ransomware, with systems encrypted and stolen information later published.
Show more events (1)
2020-09
Egregor first observed
Egregor emerged as a ransomware-as-a-service operation during the decline of Maze.

Sources

Egregor — S0554
MITRE ATT&CK
Framework
The Egregor Ransomware
CERT-FR / ANSSI
Threat Assessment: Egregor Ransomware
Palo Alto Networks Unit 42
Vendor research
Show more sources (3)