What is Egregor Ransomware? One of the Worst Threats of 2020 | UpGuard
ID: 567e626a-5858-5122-a755-509df333c2ab
STIX ID: report--567e626a-5858-5122-a755-509df333c2ab
Feed Name: UpGuard Blog
Egregor is a ransomware-as-a-service criminal group active since September 2020 that conducts double-extortion attacks—breaching networks, exfiltrating data, encrypting systems, and publishing stolen data to pressure victims—having impacted dozens of organizations including Barnes & Noble, Crytek, Ubisoft and others; the report details their malware lineage (links to Maze/Sekhmet), infection chains (loaders and commodity malware like Qakbot/Ursnif/IceID), typical TTPs (disabling AV, enabling RDP, ransom notes), and provides mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
