Netskope Threat Labs

Egregor

ATP Sandbox Adv. Heuristics

Egregor is a ransomware as a service operation first observed in September 2020. Researchers noted code similarities between Egregor and the Sekhmet and Maze ransomware families, tying it to the ecosystem that preceded it.

First seen
March 2022
Last seen
October 2026

25 techniques across 7 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1033System Owner/User Discovery
  • T1049System Network Connections Discovery
  • T1069Permission Groups Discovery
  • T1082System Information Discovery
  • T1124System Time Discovery

TA0009 Collection

  • T1039Data from Network Shared Drive

TA0011 Command and Control

TA0040 Impact

  • T1486Data Encrypted for Impact

TA0112 Defense Impairment

  • T1484Domain or Tenant Policy Modification
  • T1685Disable or Modify Tools
Alert Name
Win32.Ransomware.Egregor