logo

What is Egregor Ransomware? One of the Worst Threats of 2020 | UpGuard

ID: 567e626a-5858-5122-a755-509df333c2ab

STIX ID: report--567e626a-5858-5122-a755-509df333c2ab

Feed Name: UpGuard Blog

Threat Score
75/100

Date Published: 2023-11-16

Date Updated: 2026-05-01

...
...

Egregor is a ransomware-as-a-service criminal group active since September 2020 that conducts double-extortion attacks—breaching networks, exfiltrating data, encrypting systems, and publishing stolen data to pressure victims—having impacted dozens of organizations including Barnes & Noble, Crytek, Ubisoft and others; the report details their malware lineage (links to Maze/Sekhmet), infection chains (loaders and commodity malware like Qakbot/Ursnif/IceID), typical TTPs (disabling AV, enabling RDP, ransom notes), and provides mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.