logo

Egregor: The New Ransomware Variant to Watch

ID: e71e5bb5-5926-552b-9c21-64a17bb59a76

STIX ID: report--e71e5bb5-5926-552b-9c21-64a17bb59a76

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2020-11-24

Date Updated: 2026-04-29

...
...

Egregor is a financially motivated ransomware group observed since 25 September 2020 that uses a double‑extortion model—encrypting victim files and threatening to publish stolen data on an “Egregor News” dark‑web leak site. The group demonstrated rapid growth (71 named victims across 19 industries as of 17 Nov 2020, with a large share in Industrial Goods & Services and the US), employs anti‑analysis techniques and process injection (into iexplore.exe), and has been linked to high‑profile incidents (Barnes & Noble, Ubisoft, Crytek); the report maps their observed behaviors to MITRE ATT&CK techniques and provides mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.