Skip to content

Everest

Everest is a Russia-linked, Russian-speaking ransomware and extortion operation active since at least late 2020.

Profile source: Mallory opens in a new tab

Everest

Family profile

Everest is a Russia-linked, Russian-speaking ransomware and extortion operation active since at least late 2020. It has used double extortion, combining data theft, file encryption, and threats to publish stolen data, and later increasingly emphasized encryptionless data-theft extortion. The operation has also acted as an initial-access broker, reselling footholds in compromised networks and, at times, using data obtained by other actors for extortion.

Everest has targeted organizations in government, healthcare, telecommunications, finance, manufacturing, transportation, and other sectors across North America, Europe, and Asia. Reported intrusion methods include phishing, exploitation of vulnerable public-facing applications, and use of stolen credentials.

Observed Everest ransomware payloads are .NET-based and use obfuscation and anti-analysis protections. The encryptor can terminate security and analysis tools, disable Windows security controls, delete shadow copies and backup-related data, remove anti-ransomware protections, and self-delete after execution. It uses geofencing to avoid systems configured for Commonwealth of Independent States locales and can use Wake-on-LAN broadcasts to activate sleeping systems before encryption. File encryption uses symmetric cryptography with asymmetric protection of encryption keys; larger files may be only partially encrypted to accelerate impact across large data volumes. Data theft, where conducted, appears to occur through tooling separate from the encryptor.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access

Operational record

1
YARA rules
1
Ransom notes
2
Leak sites
2 available

Credential Theft

  • ProcDump

Discovery Enum

  • SoftPerfect NetScan

Offsec

  • Cobalt Strike
  • Metasploit
  • Meterpreter

RMM Tools

  • AnyDesk
  • Atera
  • Splashtop

Recent claims

Reported operators

Threat actors

2 named in public reporting
EVEREST

"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."

BlackByte

"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."

MITRE ATT&CK

Everest in ATT&CK

32 distinct techniques

Reporting

Research mentioning Everest

Jul 23
Cyberveille

Stadler Rail refuse de payer 10 millions CHF au gang Everest après une intrusion sur une plateforme fournisseur | CyberVeille

Stadler Rail said a cyberattack targeted a data-exchange platform operated by one of its suppliers after attackers obtained compromised login credentials, allowing access to certain technical data. The company said its own internal IT systems were not breached, production continued normally, and no sensitive personal data was stolen; it also reported that the incident did not create any safety risk and later indicated the situation was under control. The attackers were identified as the Everest group, which reportedly demanded 10 million Swiss francs in ransom after the data theft. Stadler said it would not pay, filed a criminal complaint, and stated that no confirmed data loss had been established beyond the accessed supplier-platform information.

Jul 23
Help Net Security

Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack - Help Net Security

Jul 23
Teiss News

teiss - News - Stadler Rail confirms cyberattack, refuses $12.3 million ransom demand from Everest hackers

Jul 23
Register Security

Stadler Rail scoffs at Everst’s $12.3M extortion attempts

Jul 22
The Record Media

Swiss train maker Stadler refuses Everest $12 million ransomware demand | The Record from Recorded Future News

Jul 22
Bleeping Computer

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Jul 21
Cyberveille

Stadler Rail refuse de payer une rançon de 10 millions au groupe Everest après vol de données | CyberVeille

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.