Description
Egregor is a ransomware as a service operation first observed in September 2020. Researchers noted code similarities between Egregor and the Sekhmet and Maze ransomware families, tying it to the ecosystem that preceded it.
Stats
- First seen
- March 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
25 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1027.002Software Packing
- T1036Masquerading
- T1036.004Masquerade Task or Service
- T1055Process Injection
- T1140Deobfuscate/Decode Files or Information
- T1197BITS Jobs
- T1218System Binary Proxy Execution
- T1497Virtualization/Sandbox Evasion
- T1497.003Time Based Checks
- T1497Virtualization/Sandbox Evasion
- T1497.003Time Based Checks
- T1574Hijack Execution Flow
- T1574.001DLL
TA0007 Discovery
TA0009 Collection
- T1039Data from Network Shared Drive
TA0011 Command and Control
TA0040 Impact
- T1486Data Encrypted for Impact
Alert name variants
| Alert Name |
|---|
| Win32.Ransomware.Egregor |