HackerFeeds
All ransomware groups

everest

365 tracked victims
·first seen 2021-09-09·last activity 2026-05-29

Group profile

Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage.

MITRE ATT&CK TTPs

TA0005

Stealth

  • T1027Obfuscated Files or Information

    Binary protected with ConfuserEx: rename obfuscation, constants encryption, integer confusion, and modified module .cctor.

  • T1027.007Obfuscated Files or Information: Dynamic API Resolution

    All non-corlib native API calls resolved at runtime via LoadLibrary / GetProcAddress rather than static imports.

  • T1078.003Valid Accounts: Local Accounts

    Implicit current-user impersonation used for net use \\<unc> connections to discovered network shares without explicit credential passing.

  • T1112Modify Registry

    Multiple HKCU/HKLM registry writes: LongPathsEnabled, LocalAccountTokenFilterPolicy, EnableLinkedConnections (share access), WallPaper (ransom note), AppName\PublicKey (encryption key storage).

  • T1140Deobfuscate/Decode Files or Information

    Runtime decryption of UserStrings via <Module>.m using GZip decompression followed by Base64 decoding.

  • T1480Execution Guardrails

    Global <GUID> mutex enforces single-instance execution; CIS culture/LCID geo-fence prevents execution on CIS-locale systems.

  • T1564Hide Artifacts

    Process self-DACL set to deny-Everyone via KZsyzkgZlDQw.UB, preventing other processes from inspecting or terminating the ransomware process.

  • T1622Debugger Evasion

    Memory-pig killer heuristic: processes consuming more than 250 MB are terminated, targeting sandbox environments and active debuggers.

TA0007

Discovery

  • T1018Remote System Discovery

    ARP table parsed via arp -a; ARP-driven Wake-On-LAN packets sent to discovered hosts to bring them online before encryption.

  • T1135Network Share Discovery

    Network shares enumerated via net view, NetDfsEnum, WNetEnumResource*, Win32_Share WMI class, and Win32_NetworkConnection.

  • T1518.001Software Discovery: Security Software Discovery

    Anti-analysis kill list matched against ProcessName and MainWindowTitle to identify and terminate security/analysis tools.

  • T1614.001System Location Discovery: System Language Discovery

    CIS culture/LCID check used as exclusion geo-fence; execution aborts if system locale matches CIS-region languages.

TA0008

Lateral Movement

  • T1021.002Remote Services: SMB/Windows Admin Shares

    net.exe use \\<unc> executed over discovered SMB shares to access and encrypt remote file systems.

TA0011

Command and Control

  • T1071.001Application Layer Protocol: Web Protocols

    WebClient.DownloadData referenced in Helpers.DownloadUrl — present in code but not reachable at runtime (inert code path).

TA0040

Impact

  • T1486Data Encrypted for Impact

    AES-128-CBC PKCS#7 / NoPadding (large files) encryption of all eligible files on local drives, mounted unlettered volumes, and LAN shares.

  • T1489Service Stop

    ServiceController.Stop called against ~100 services (AV, backup, MSSQL, Exchange, MBAM, Veeam, Acronis, etc.) combined with sc config <svc> start=disabled to prevent restart.

  • T1490Inhibit System Recovery

    VSS deletion via PowerShell or vssadmin, SRRemoveRestorePoint, backup file deletion (del /s /q), Recycle Bin removal (rd /s /q), Restart Manager used to force-shutdown apps locking target files.

Recent victims

showing 50 of 365
DateWebsite / victimSectorCountry
2026-05-29
asopagos.com
Asopagos S.A.asopagos.com
Not FoundCO
2026-05-29
Е
ЕРМ
Business Services
2026-05-28
spedition-kern.com
Spedition Kernspedition-kern.com
Transportation/LogisticsDE
2026-05-28
advancedpsychiatryassociates.com
Advanced Psychiatry Associatesadvancedpsychiatryassociates.com
HealthcareUS
2026-05-28
sidrakwhospital.com
Sidra Kuwait Hospitalsidrakwhospital.com
HealthcareKW
2026-05-28
vvo.de
VVO Financevvo.de
Financial ServicesDE
2026-05-28
A
AKM
Not FoundJP
2026-05-28Transportation/LogisticsUS
2026-05-28
fortheface.com
L&P Aestheticsfortheface.com
HealthcareUS
2026-05-07
R
Rehab Clinics Group Ltd
HealthcareGB
2026-05-05
S
Studio Marchi - Studio Professionale Associato
Business ServicesIT
2026-05-03Financial ServicesUS
2026-05-02Business ServicesCA
2026-05-02Financial ServicesUS
2026-05-02
epiqglobal.com
Epiq Globalepiqglobal.com
Business ServicesUS
2026-04-30
L
Liberty Mutual Insurance
Financial ServicesUS
2026-04-30TechnologyUS
2026-04-28
I
Indonesia's Customs Analytics Platform
Public SectorID
2026-04-28
super.ai
Super AIsuper.ai
TechnologyDE
2026-04-20Agriculture and Food ProductionUS
2026-04-20
umilesgroup.com
Umiles Groupumilesgroup.com
Business ServicesES
2026-04-20
complete-aircraft.com
Complete Aircraft Groupcomplete-aircraft.com
ManufacturingUS
2026-04-20Consumer ServicesID
2026-04-20
citizensbank.com
Citizens Bankcitizensbank.com
Financial ServicesUS
2026-04-20
frostbank.com
Frost Bankfrostbank.com
Financial ServicesUS
2026-04-13
ksubsea-group.com
K Subsea Groupksubsea-group.com
EnergySG
2026-04-01
N
Nissan
ManufacturingJP
2026-03-31
petoabre.com
Parque Eólico Toabrépetoabre.com
EnergyPA
2026-03-31
brantas-abipraya.co.id
PT Brantas Abiprayabrantas-abipraya.co.id
ConstructionID
2026-03-30
straight-line-transport.com
Straight Line Logisticsstraight-line-transport.com
Transportation/LogisticsAE
2026-03-15
norstella.com
Evaluate a Norstella companynorstella.com
Not FoundNO
2026-03-10
1fpg.com
First Priority Group1fpg.com
ManufacturingUS
2026-03-06
hyundaielevator.co.kr
Hyundai Elevatorhyundaielevator.co.kr
ManufacturingKR
2026-02-28ManufacturingJP
2026-02-25
1
111
Not Found
2026-02-24ManufacturingPL
2026-02-17
A
Atlas Air: MUSE INSECURE
Transportation/LogisticsUS
2026-02-11
tsunamitsolutions.com
Tsunami Tsolutionstsunamitsolutions.com
TechnologyUS
2026-02-06
atlasair.com
Atlas Airatlasair.com
Transportation/LogisticsUS
2026-02-02TechnologyUS
2026-02-02
ironmountain.com
Iron Mountainironmountain.com
Business ServicesUS
2026-02-01
shinwa.co.jp
Shinwa Co Ltdshinwa.co.jp
ConstructionJP
2026-02-01
hosokawamicron.co.jp
Hosowaka Micron Grouphosokawamicron.co.jp
ManufacturingJP
2026-02-01Business ServicesGB
2026-02-01
acutranssolutions.com
Acu Trans Solutions LLCacutranssolutions.com
Transportation/LogisticsUS
2026-02-01
sigma-pa.de
SIGMA Processing Groupsigma-pa.de
Not FoundDE
2026-01-21TechnologySG
2026-01-20
C
Ciena
TelecommunicationUS
2026-01-20
V
Virginia Records - Database leaked
Not FoundBG
2026-01-20
mcdindia.com
McDonalds Indiamcdindia.com
Hospitality and TourismIN