Description Summary
Egregor emerged in September 2020 and rapidly absorbed affiliates after the Maze operation wound down, becoming a leading double-extortion brand of late 2020. Its code is a variant of the Sekhmet family (not Maze's), but it used the same RaaS plus leak-site model. High-profile victims included Ubisoft, Barnes & Noble, Kmart, and Cencosud. Ukrainian, French, and U.S. authorities disrupted the operation with arrests in February 2021; decryption keys were later published.
Threat Actor
RaaS with ex-Maze affiliates; Sekhmet code lineage. Disrupted by international law enforcement in February 2021.
Technical Indicators
Encryption Extension
Random extension per victim
Encryption Algorithm
ChaCha20 (files) + RSA-2048 (key wrapping)
Ransom Note Name
RECOVER-FILES.txt
Targeted Industries
Retail, Manufacturing, Technology, Logistics
First Seen
September 2020
Last Seen
February 2021 (arrests; keys published 2022)
Geographical Location
North America, Europe, Latin America
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 2 | T1566 | Phishing |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059.001 | PowerShell |
| Defense Evasion x 2 | T1218.011 | Signed Binary Proxy Execution: Rundll32 |
| T1562.001 | Disable or Modify Tools | |
| Lateral Movement x 1 | T1021.001 | Remote Services: RDP |
| Exfiltration x 1 | T1567.002 | Exfiltration to Cloud Storage |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |