Egregor: The New Ransomware Variant to Watch
ID: e71e5bb5-5926-552b-9c21-64a17bb59a76
STIX ID: report--e71e5bb5-5926-552b-9c21-64a17bb59a76
Feed Name: ReliaQuest Blog
Egregor is a financially motivated ransomware group observed since 25 September 2020 that uses a double‑extortion model—encrypting victim files and threatening to publish stolen data on an “Egregor News” dark‑web leak site. The group demonstrated rapid growth (71 named victims across 19 industries as of 17 Nov 2020, with a large share in Industrial Goods & Services and the US), employs anti‑analysis techniques and process injection (into iexplore.exe), and has been linked to high‑profile incidents (Barnes & Noble, Ubisoft, Crytek); the report maps their observed behaviors to MITRE ATT&CK techniques and provides mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
