Credential Theft
- ProcDump
Everest is a Russia-linked ransomware operation active since at least 2020 and commonly described as a ransomware-as-a-service group.
Profile source: Mallory opens in a new tabEverest
Everest is a Russia-linked ransomware operation active since at least 2020 and commonly described as a ransomware-as-a-service group. It has conducted double-extortion campaigns in which victims’ data is stolen and systems may be encrypted, followed by threats to publish the data if payment is refused. Over time, Everest has increasingly shifted from traditional network encryption toward data-theft-focused extortion, and it has also been associated with initial access brokering and resale of compromised network access to other threat actors. Reporting also indicates the group has at times used data obtained by other actors in its own extortion activity and has attempted to recruit corporate insiders.
Everest has targeted organizations across multiple sectors, including government, healthcare, telecommunications, transportation, finance, manufacturing, aviation, and technology, with victims reported in North America, Europe, and Asia. Publicly claimed incidents and reporting tie the group to compromises involving third-party suppliers and shared platforms as well as direct enterprise intrusions. Observed access methods associated with Everest include exploitation of vulnerable public-facing applications, phishing, and use of stolen or compromised credentials.
Technical analysis of the Everest encryptor shows a Windows-focused .NET ransomware payload protected with ConfuserEx. The malware performs file encryption while emphasizing defense evasion and operational disruption. Documented behaviors include mutex-based single-instance control, geofencing to avoid systems configured for CIS-language locales, termination of security and analysis tools, disabling Windows Defender Controlled Folder Access, deletion of shadow copies, removal of backup-related data, and self-deletion after execution. The encryptor has also been observed using Wake-on-LAN to wake sleeping devices so they can be encrypted. Analysis of one live sample found no built-in data exfiltration capability, indicating that theft in Everest incidents may occur earlier in the intrusion through separate tooling rather than through the ransomware binary itself.
Everest remains notable for blending ransomware, pure extortion, and access-broker activity, making it relevant both as a malware family and as a broader criminal operation.
Reported operators
"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."
"This latest blog documents the TTPs employed by a group who were observed deploying Everest ransomware during a recent incident response engagement."
MITRE ATT&CK
Reporting
Stadler Rail said a cyberattack targeted a data-exchange platform operated by one of its suppliers after attackers obtained compromised login credentials, allowing access to certain technical data. The company said its own internal IT systems were not breached, production continued normally, and no sensitive personal data was stolen; it also reported that the incident did not create any safety risk and later indicated the situation was under control. The attackers were identified as the Everest group, which reportedly demanded 10 million Swiss francs in ransom after the data theft. Stadler said it would not pay, filed a criminal complaint, and stated that no confirmed data loss had been established beyond the accessed supplier-platform information.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.