Ransomware Group intelligence
Everest
ActiveTrack Everest with 426 published victims and 2 known leak locations in a single intelligence view.
Overview
Everest is tracked by Breach House as a ransomware group with 426 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 4h ago | ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion |
| Leak location 2 | Onion service | Up checked 4h ago | everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion |
Top Activity Sectors (16)
- Not identified 108
- Finance / Legal / Insurance 51
- Healthcare / Pharma 45
- Communication / Marketing 43
- Services 36
- IT 27
- Manufacturing / Engineering 15
- Transportation / Travel / Logistics 15
- Energy 14
- Construction / Real Estate 10
- Retail / E-commerce 7
- Public Sector 7
- Agriculture / Food 6
- Hospitality / Food & Beverage / Tourism 6
- Telecommunications 5
- Education 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Everest, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: everest uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: everest modifies Windows Registry Run Keys to ensure ransomware execution persists across reboots on compromised hosts.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: everest disables or modifies security tools like antivirus software to evade detection during initial compromise and execution phases.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: everest deletes Volume Shadow Copies and backup directories via system commands to prevent data recovery without payment.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: everest accesses LSASS memory using credential-stealing tools to harvest user credentials for lateral access and evasion.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: everest performs network share discovery to identify accessible remote directories for lateral movement and victim data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: everest exploits SMB/Windows Admin Shares for lateral movement between networked systems within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: everest encrypts victim files using custom ransomware binaries to maximize impact and force ransom payments.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: everest executes Service Stop commands to terminate critical services, disrupting operational continuity during ransomware deployment.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: everest invokes system recovery inhibition commands to prevent backup restoration and isolate compromised machines.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (8)
▼Software Everest has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
EVERESTRANSOMWARE.txt
Dear [snip], Greetings from the Everest team. Your systems have been attacked, the files are encrypted. You can read about us in our blog (Tor browser needed) Blog : ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion Or read about our group in Twitter Also, our team was able to bypass your "Dataprotection" as any other your protection software and more than 1 Terabyte of internal files were exfiltrated to our servers, which we can confirm with great joy and ease The list contains financial documents, internal orders, KYC information(documents,photos...), trusted representatives personal info Client risk levels,loans, debt and client data. Various financial documentation, backups , etc. etc. The information was collected both from personal PCs and from centralized storage locations. If an agreement is reached with us, this information will never be published and the problem will disappear as if it never happened, otherwise it will be posted on our blog and darknet. Which will lead to even greater financial and reputational losses on your part. Also you will get 1.Attack logbook (months of experience with your company) with full list of vulnerabilities and bypass methods 2.Advices how to singifically improve your security and avoid such attacks in the future 3.We will delete all files from your company 4.We will attack your company no more Yours trully Everest Team Email to contact: [email protected] Your key: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (426)
Search, filter and paginate the victim timeline for Everest. Showing 301–400 of 426.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Agriloja pt.3 id8328 View details | Portugal | Agriculture / Food | ||
|
New leakage 3 GB of internal documents .Company must stop ignore our calls and contact us in next 36 hrs.Full package of 1.2 TB uploading and will be published in case of silence.https://dropmefiles.com/Z4pIjPassword: 69hrZT |
|||||
| Ransomware | Agriloja.pt demo-leak id8183 View details | Agriculture / Food | |||
|
100 random personal records (from 1400+). Company must contact us in next 24 hrs. Otherwise more personal data will be published in the blog and darknet forums. Download: https://dropmefiles.com/L8kHr https://dropmefiles.com.ua/ua/vKTzPassword: 123 |
|||||
| Ransomware | Agriloja.pt id8132 View details | Portugal | Agriculture / Food | ||
|
464574 internal documents and files stolen.1.2 TBSQL DBs, Email Archives, Personal information,employee data,,IDs,various company documents… To restore damaged system and prevent data from publication company’s representative should contact us in next 72 hrs. Full filetree can be provided as a proof. |
|||||
| Ransomware | ZESA Holdings id8084 View details | India | Finance / Legal / Insurance | ||
|
Today, the servers of the entire infrastructure of ZESA HOLDINGS (90% Country Electricity Manufacture ) were attacked, including divisionsZETDCZENTPowertelICS, IPMP, Smartvend ,various oracle servers, big part of backups were also attacked.Terabytes of internal (and interesting) data has been exfiltrated to our servers Internal financial data (Including WorldBank’s data and Indian Bank transactions and documents) Various […] |
|||||
| Ransomware | Kovair Software Data Leak id8062 View details | IT | |||
|
The set dates are out, so we post the entire archive Part1 https://dropmefiles.com/3GRYp Part2 https://dropmefiles.com/nAayA Part3 https://dropmefiles.com/tmhIh Part4 https://dropmefiles.com/K5zYz Part5 https://dropmefiles.com/6rp1U Part6 https://dropmefiles.com/5j6VM Password: &#B”a3Arcj}eOfoQ==Fh |
|||||
| Ransomware | Great Opportunity to monetize your corporate access id7994 View details | Telecommunications | |||
|
Team looking for new partners with access to corporate networks.Fast work, good share. The offer will close on August 7. First come first served jabber:[email protected]@thesecure.biz email:[email protected]@cock.li |
|||||
| Ransomware | Kovair Software id7944 View details | IT | |||
|
200 GB of internal files (Kovair.com) were stolen from the company’s servers. The files contain:– Project Source Codes– Personal data of employees– Various internal work documents To fully restore the system and delete these files, company representatives must contact by August 3, 2023.Otherwise, all this data will be published here and other forums,in the same […] |
|||||
| Ransomware | US District Court / Law company id6268 View details | Finance / Legal / Insurance | |||
|
On sale access to the network US District CourtEmployee access,full controlAV: NoNetwork access of a lawyer with tons various confidential documents is included in this sale. Internal correspondence,tax,banks,ssn,dl,court cases. State IL.Price 15,000$Payment: btc,xmrContact email: [email protected] or jabber: [email protected],[email protected] |
|||||
| Ransomware | US District Court IL / On sale id6189 View details | Finance / Legal / Insurance | |||
|
On sale access to the network US District Court Employee access,full control AV: No Network access of a lawyer with tons various confidential documents is included in this sale Contact email: [email protected] or jabber: [email protected],[email protected] |
|||||
| Ransomware | US District Court / On sale id6185 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MultiCareInc pt.2 id6046 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | US District Court id5811 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NRG Innovations DataBase Leak id5710 View details | Finance / Legal / Insurance | |||
|
Includes internal correspondence,financial documents,tax documents,accounting,SSN,DLThe owners of the company were notified of the incident in person and of the time frame.Download:https://dropmefiles.com.ua/ua/Z4aW2https://dropmefiles.com.ua/ua/******* site pwd 868274903rar pwd 8392GLDKLA82@ |
|||||
| Ransomware | Aeronautics company Canada | UTC Aerospace Systems, Bombardier, NASA partners id5188 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aeronautics company Canada / UTC Aerospace Systems, Bombardier aerospace, NASA partners id4645 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aeronautics company Canada / UTC Aerospace Systems, Bombardier aerospace partners id4640 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aeronautics company Canada / Production of parts for aircraft engines id4613 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aeronautics company Canada id4562 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AT&T id4400 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stages Pediatric Care DataBase on Sale id4395 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rundle Eye Care DataBase Leak id4389 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stages Pediatric Care New 40 personal records id4369 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Stages Pediatric Care New 250 personal records id4368 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | MultiCareInc pt.3 id4359 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MultiCareInc DataBase Leak id4358 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stages Pediatric Care new personal data id4357 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MultiCare DataBase Leak id4345 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Electricity company / Air Defense Solutions company id4340 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Electricity company pt.3 id4337 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MultiCare pt.3 id4334 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stages Pediatric Care Update id4322 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Electricity company pt.2 id4314 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | RS.GOV.BR/Government Brazil id4312 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Electricity company id4304 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SPERONI S.P.A / Data Lamborghini, Ferrari, Fiat Group, VAG, Brembo id4303 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rundle Eye Care id4299 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MultiCare pt.2 id4298 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MultiCare Home Health id4270 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stages Pediatric Care id4258 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FederalBank/Fedfina DataBase Leak id4235 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ministerio de Economía Argentina id4220 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Government Brazil id4201 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FederalBank/Fedfina.part5 id4181 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GOV Brazil id4049 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Olamgroup id4004 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FederalBank/Fedfina.part4 id3865 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FederalBank/Fedfina.part3 id3844 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FederalBank/Fedfina.part2 id3828 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FederalBank / Fedfina id3811 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pontal Engineering Constructions and Developments Files Leak id3764 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pontal Engineering Constructions and Developments id3736 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Amalfitana Gas Srl id3706 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FAYAT id3681 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Metek PLC Files Leak id3631 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Metek Plc id3619 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | VTVCAB id3603 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Lamborghini, Ferrari, Fiat Group, VAG, Brembo And data from other automobile concerns id3543 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Limited May Access Sale id3349 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Collegiate sports medicine id3340 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Reckitt Benckiser id3219 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Standard Building Supplies Ltd. id3188 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Standard Building Supplies Ltd id3159 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Supplies Company Data Leak in British Columbia, Canada id3155 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | United States of America GOV id3104 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ministry of Economy and Finance of Peru id2945 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | South Africa Electricity company id2872 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Instituto Nacional de Tecnología Agropecuaria id2836 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | UK GOV id2828 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | News id2827 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | XEFI / Neocyber id2820 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SPERONI SpA id2813 View details | Other | — | ||
|
SPERONI SpA is an Italian engineering and manufacturing company headquartered in Cassine, specializing in the production of high-precision tool presetters and measuring systems for the global machining industry. The firm provides advanced solutions designed to optimize manufacturing workflows and ensure quality control in complex production environments. As a prominent player in the industrial technology sector, the organization maintains a significant international footprint. SPERONI SpA has been listed as a ransomware victim associated with the threat actor group known as Everest. |
|||||
| Ransomware | XEFI id2801 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Turner Construction Company id2795 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | IDFC FIRST Bank id2792 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ledcor id2791 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BEAUTYWEST, INC. id2788 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gershon Biegeleisen & Co id2787 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Backus, Meyer & Branch, LLP id2786 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Greenberg & Stein New York City Personal Injury Lawyers id2784 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Law Offices of Brandon Sua & Associates id2783 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Campbell Sales and Service, Inc id2782 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Federal land inc. id2781 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centro Hospitalar de Setúbal id2779 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Signum id2673 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Various accesses on sale id2660 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Weir & Partners LLP id2603 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Florida lawyer’s data leaked id2525 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gardenworks id2474 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AFG Canada id2465 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Partnership id2453 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Huhtamaki id2407 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SPERONI SPA id2261 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Jeffmoss id2153 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ktmtriallaw id2152 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Saand id2075 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Seldin id2063 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Black Friday has arrived id1999 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Società Italiana degli Autori ed Editori / Information updated id1982 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Argentina GOV id1978 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Charlie Hebdo id1960 View details | Other | — | ||
|
No additional victim description available. |
|||||