Credential Theft
- ProcDump
Everest is a Russia-linked, Russian-speaking ransomware and extortion operation active since at least late 2020.
Profile source: Mallory opens in a new tabEverest
Everest is a Russia-linked, Russian-speaking ransomware and extortion operation active since at least late 2020. It has used double extortion, combining data theft, file encryption, and threats to publish stolen data, and later increasingly emphasized encryptionless data-theft extortion. The operation has also acted as an initial-access broker, reselling footholds in compromised networks and, at times, using data obtained by other actors for extortion.
Everest has targeted organizations in government, healthcare, telecommunications, finance, manufacturing, transportation, and other sectors across North America, Europe, and Asia. Reported intrusion methods include phishing, exploitation of vulnerable public-facing applications, and use of stolen credentials.
Observed Everest ransomware payloads are .NET-based and use obfuscation and anti-analysis protections. The encryptor can terminate security and analysis tools, disable Windows security controls, delete shadow copies and backup-related data, remove anti-ransomware protections, and self-delete after execution. It uses geofencing to avoid systems configured for Commonwealth of Independent States locales and can use Wake-on-LAN broadcasts to activate sleeping systems before encryption. File encryption uses symmetric cryptography with asymmetric protection of encryption keys; larger files may be only partially encrypted to accelerate impact across large data volumes. Data theft, where conducted, appears to occur through tooling separate from the encryptor.
Reported operators
"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."
"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."
MITRE ATT&CK
Reporting
Stadler Rail said a cyberattack targeted a data-exchange platform operated by one of its suppliers after attackers obtained compromised login credentials, allowing access to certain technical data. The company said its own internal IT systems were not breached, production continued normally, and no sensitive personal data was stolen; it also reported that the incident did not create any safety risk and later indicated the situation was under control. The attackers were identified as the Everest group, which reportedly demanded 10 million Swiss francs in ransom after the data theft. Stadler said it would not pay, filed a criminal complaint, and stated that no confirmed data loss had been established beyond the accessed supplier-platform information.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.