logo

The Locking Egregor

ID: 818fcf80-2ba4-5f36-aba2-15270a1fa5ae

STIX ID: report--818fcf80-2ba4-5f36-aba2-15270a1fa5ae

Feed Name: Group-IB Blog

Threat Score
85/100

Date Published: 2020-11-20

Date Updated: 2026-04-27

...
...

Egregor is a Big-Game-Hunting ransomware family active since September 2020 that has hit at least 69 companies worldwide; operators use Qakbot for initial access, Cobalt Strike and lateral movement tools (PsExec, AdFind, RDP tweaks) for post-exploitation, and Rclone for data exfiltration before encrypting files with ChaCha8 and RSA-2048. The report includes sample-level malware analysis (DLL delivery via rundll32, multi-layer decryption, obfuscation), observed IoCs (e.g., q.dll, md.exe, RECOVER-FILES.txt, renamed svchost.exe), published data-leak activity, and prioritized detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.