Egregor

MITRE ATT&CK: S0554 View on attack.mitre.org

Aliases: Egregor

First seen
2020-09-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
10 (10 malicious)
Last IoC activity
2026-08-12 11:12:29
Profile updated
2026-07-07 12:57:16

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications media-and-entertainment

Context

Egregor is a Ransomware-as-a-Service (RaaS) tool that was first observed in September 2020. Researchers have noted code similarities between Egregor and Sekhmet ransomware, as well as Maze ransomware.

Recent IoC activity

10 malicious indicators in Maltiverse are attributed to Egregor (S0554). The 10 most recently updated:

Detection coverage

  • 4 YARA rules
  • 761 Sigma rules

Malware & tools used

  • Time Based Checks (attack-pattern)
  • Rundll32 (attack-pattern)
  • BITS Jobs (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Software Packing (attack-pattern)
  • Data from Network Shared Drive (attack-pattern)
  • Native API (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • DLL (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Domain Groups (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Web Protocols (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Group Policy Modification (attack-pattern)
  • Process Injection (attack-pattern)
  • PowerShell (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

Detection rules

  • TRELLIX_ARC_Ransom_Egregor (yara-rule)
  • ARKBIRD_SOLG_Ran_Egregor_Sept_2020_1 (yara-rule)
  • ARKBIRD_SOLG_Ran_Egregor_Oct_2020_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Egregor (yara-rule)

Related threat objects

Reports & references

  • analyst1.com — Ransom Mafia Analysis Of The World%E2%80%99S First Ransomware Cartel (report)
  • CrowdStrike — Report2021Gtr (report)
  • analyst1.com — Ransom Mafia Analysis Of The Worlds First Ransomware Cartel (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • CrowdStrike — Prophet Spider Exploits Oracle Weblogic To Facilitate Ransomware Activity (report)
  • domaintools.com — The Most Prolific Ransomware Families A Defenders Guide (report)
  • Cisco Talos — Ctir Trends Winter 2020 21 (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
  • krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • therecord.media — Ransomwhere Project Wants To Create A Database Of Past Ransomware Payments (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • accenture.com — Evolving Danger Ransomware Extortion (report)
  • bleepingcomputer.com — Darkside Ransomware Made 90 Million In Just Nine Months (report)
  • cert.ssi.gouv.fr — Certfr 2021 Cti 009 (report)
  • cert.ssi.gouv.fr — Certfr 2021 Cti 009 (report)
  • coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • huntandhackett.com — Advanced Ip Scanner The Preferred Scanner In The Apt Toolbox (report)
  • blog.chainalysis.com — Ransomware Connections Maze Egregor Suncrypt Doppelpaymer (report)
  • zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)

External references