Egregor Ransomware

Description Summary

Egregor emerged in September 2020 and rapidly absorbed affiliates after the Maze operation wound down, becoming a leading double-extortion brand of late 2020. Its code is a variant of the Sekhmet family (not Maze's), but it used the same RaaS plus leak-site model. High-profile victims included Ubisoft, Barnes & Noble, Kmart, and Cencosud. Ukrainian, French, and U.S. authorities disrupted the operation with arrests in February 2021; decryption keys were later published.

Threat Actor

RaaS with ex-Maze affiliates; Sekhmet code lineage. Disrupted by international law enforcement in February 2021.

Technical Indicators

Encryption Extension
Random extension per victim
Encryption Algorithm
ChaCha20 (files) + RSA-2048 (key wrapping)
Ransom Note Name
RECOVER-FILES.txt
Targeted Industries
Retail, Manufacturing, Technology, Logistics
First Seen
September 2020
Last Seen
February 2021 (arrests; keys published 2022)
Geographical Location
North America, Europe, Latin America

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 2 T1566 Phishing
T1078 Valid Accounts
Execution x 1 T1059.001 PowerShell
Defense Evasion x 2 T1218.011 Signed Binary Proxy Execution: Rundll32
T1562.001 Disable or Modify Tools
Lateral Movement x 1 T1021.001 Remote Services: RDP
Exfiltration x 1 T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop