Egregor Operators shattered

The Egregor ransomware gang has been active since September 2020, it began operating shortly after the Maze ransomware operators shut down their operations.Like other ransomware operators, the gang implements a…
Egregor hits Randstand & Vancouver Metro

Egregor hits Randstand & Vancouver Metro

Egregor is a new organized cybercrime ransomware-as-a-service operation that partners with affiliates to compromise networks and deploy their ransomware. The ransomware gang began operating in the middle of September 2020…

Qakbot 🐎 ->Prolock ☠️-> Egregor 👹

Group-IB discovered that QakBot (aka Qbot) operators have abandoned ProLock for Egregor ransomware. ProLock = Egregor The analysis of attacks where Egregor has been deployed revealed that the TTPs used…

Egregor strikes printers

The Egregor ransomware uses a novel approach to get a victim's attention after an attack - shoot ransom notes from all available printers. Ransomware gangs know that many businesses would…

Maze shutting down finally 💫

The Maze cybercrime gang is shutting down its operations that began its operation in may 2019 after rising to become one of the most prominent players performing ransomware attacks. A…

Egregor Ransomware ! Blessing in disguise

A recently uncovered ransomware variant called Egregor that appears to have infected about a dozen organizations worldwide over the past several months, like other gangs Maze and Sodinokobi, Egregor also…