Ransomware Group intelligence
Everest
ActiveTrack Everest with 426 published victims and 2 known leak locations in a single intelligence view.
Overview
Everest is tracked by Breach House as a ransomware group with 426 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 4h ago | ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion |
| Leak location 2 | Onion service | Up checked 4h ago | everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion |
Top Activity Sectors (16)
- Not identified 108
- Finance / Legal / Insurance 51
- Healthcare / Pharma 45
- Communication / Marketing 43
- Services 36
- IT 27
- Manufacturing / Engineering 15
- Transportation / Travel / Logistics 15
- Energy 14
- Construction / Real Estate 10
- Retail / E-commerce 7
- Public Sector 7
- Agriculture / Food 6
- Hospitality / Food & Beverage / Tourism 6
- Telecommunications 5
- Education 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Everest, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: everest uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: everest modifies Windows Registry Run Keys to ensure ransomware execution persists across reboots on compromised hosts.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: everest disables or modifies security tools like antivirus software to evade detection during initial compromise and execution phases.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: everest deletes Volume Shadow Copies and backup directories via system commands to prevent data recovery without payment.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: everest accesses LSASS memory using credential-stealing tools to harvest user credentials for lateral access and evasion.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: everest performs network share discovery to identify accessible remote directories for lateral movement and victim data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: everest exploits SMB/Windows Admin Shares for lateral movement between networked systems within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: everest encrypts victim files using custom ransomware binaries to maximize impact and force ransom payments.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: everest executes Service Stop commands to terminate critical services, disrupting operational continuity during ransomware deployment.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: everest invokes system recovery inhibition commands to prevent backup restoration and isolate compromised machines.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (8)
▼Software Everest has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
EVERESTRANSOMWARE.txt
Dear [snip], Greetings from the Everest team. Your systems have been attacked, the files are encrypted. You can read about us in our blog (Tor browser needed) Blog : ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion Or read about our group in Twitter Also, our team was able to bypass your "Dataprotection" as any other your protection software and more than 1 Terabyte of internal files were exfiltrated to our servers, which we can confirm with great joy and ease The list contains financial documents, internal orders, KYC information(documents,photos...), trusted representatives personal info Client risk levels,loans, debt and client data. Various financial documentation, backups , etc. etc. The information was collected both from personal PCs and from centralized storage locations. If an agreement is reached with us, this information will never be published and the problem will disappear as if it never happened, otherwise it will be posted on our blog and darknet. Which will lead to even greater financial and reputational losses on your part. Also you will get 1.Attack logbook (months of experience with your company) with full list of vulnerabilities and bypass methods 2.Advices how to singifically improve your security and avoid such attacks in the future 3.We will delete all files from your company 4.We will attack your company no more Yours trully Everest Team Email to contact: [email protected] Your key: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (426)
Search, filter and paginate the victim timeline for Everest. Showing 401–426 of 426.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | MINISTRY OF ECONOMY AND FINANCE Peru id1948 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Police Brazil id1918 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Società Italiana degli Autori ed Editori / Data on sale id1917 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cabinet Remy Le Bonnois / Data on sale / Charlie Hebdo id1916 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cabinet Remy Le Bonnois / Data on sale id1899 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Società Italiana degli Autori ed Editori id1655 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | U.S. GOV id1556 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Kes id1499 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PRECREDIT id1477 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Steel Projects id1382 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Irish Pioneer works id1375 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | VIVA Formwork and Scaffolding id1374 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hörmanseder Stahlbau GmbH id1373 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Southland id1372 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Xmedicalpicture id1371 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Andel id1370 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GROUPE CONFIANCE IMMOBILIER id885 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cabinet Remy Le Bonnois id884 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | XEFI / Part 2 id883 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Сompilation of lawyers France id882 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AIC STEEL id881 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Weir & Partners LLP / Part 2 id880 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | InfraBuild id879 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tampa Tank INC id878 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Alispharm id877 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Orha Muvek id876 View details | Other | — | ||
|
No additional victim description available. |
|||||