Ransomware Group intelligence
Egregor
InactiveTrack Egregor with 6 published victims in a single intelligence view.
Overview
Egregor is tracked by Breach House as a ransomware group with 6 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (4)
Typical Attacks (25)
▼How Egregor typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Egregor.
-
T1059.001 PowerShell Execution
What they do: Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Egregor has used the Windows API to make detection more difficult.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Egregor has used BITSadmin to download and execute malicious DLLs.
What that means: Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks.
-
What they do: Egregor has used DLL side-loading to execute its payload.
What that means: Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses.
-
What they do: Egregor can inject its payload into iexplore.exe process.
What that means: Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: Egregor can modify the GPO to evade detection.
What that means: Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
-
T1027.002 Software Packing Stealth
What they do: Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1036.004 Masquerade Task or Service Stealth
What they do: Egregor has masqueraded the svchost.exe process to exfiltrate data.
What that means: Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Egregor has been decrypted before execution.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1218.010 Regsvr32 Stealth
What they do: Egregor has used regsvr32.exe to execute malicious DLLs.
What that means: Adversaries may abuse Regsvr32.exe to proxy execution of malicious code.
-
T1218.011 Rundll32 Stealth
What they do: Egregor has used rundll32 during execution.
What that means: Adversaries may abuse rundll32.exe to proxy execution of malicious code.
-
What they do: Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes.
What that means: Adversaries may employ various means to detect and avoid virtualization and analysis environments.
-
What they do: Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection.
What that means: Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Egregor has disabled Windows Defender to evade protections.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1033 System Owner/User Discovery Discovery
What they do: Egregor has used tools to gather information about users.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1049 System Network Connections Discovery Discovery
What they do: Egregor can enumerate all connected drives.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1069.002 Domain Groups Discovery
What they do: Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Egregor can perform a language check of the infected system and can query the CPU information (cupid).
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1124 System Time Discovery Discovery
What they do: Egregor contains functionality to query the local/system time.
What that means: An adversary may gather the system time and/or time zone settings from a local or remote system.
-
T1039 Data from Network Shared Drive Collection
What they do: Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel.
What that means: Adversaries may search network shares on computers they have compromised to find files of interest.
-
T1071.001 Web Protocols Command and Control
What they do: Egregor has communicated with its C2 servers via HTTPS protocol.
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Egregor has the ability to download files from its C2 server.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1486 Data Encrypted for Impact Impact
What they do: Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Crypto Wallets (9)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
1GJ4dp5vwK2E9PZ4eF7FVujJiTHERDTFJX |
bitcoin | $800,560 | 1 |
1Mk96FcixjayGZgdPgo4GrnPPSn7rL1jpE |
bitcoin | $496,495 | 1 |
13ELQVGgkM79nW34ncBe7Jz7xhXsXmRruM |
bitcoin | $373,900 | 1 |
1LdrbQEAersWLi6A83JrCzERyXEZWD4hBP |
bitcoin | $338,425 | 1 |
1D2ZiHwE4pQb8X6NNcXdfHwncHa3yrDdYr |
bitcoin | $313,627 | 1 |
1MPdDiRhWFawgN2GVi1Jamm8DdC4qypoGL |
bitcoin | $305,182 | 1 |
1GZV41rSAHAj63pNjLCBwo7rfioxU8JPE9 |
bitcoin | $299,378 | 1 |
112yZpAs3Va6az6JTKZ7iQZEAWdvD5DYoj |
bitcoin | $100,123 | 1 |
1PDSGRqkBF7yEJhTNDaxNm6UQT63rrzTGk |
bitcoin | $99,347 | 1 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Victims (6)
Search, filter and paginate the victim timeline for Egregor. Showing 1–6 of 6.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Center Hospitalier de Dax-Côte d’Argent id578 View details | France | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | TransLink (Metro Vancouver transit system) id533 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Kmart id534 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Cencosud id523 View details | Chile | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | SN Servicing Corporation id497 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Barnes & Noble id495 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||