Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors everest

Description

Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage. Known victims: 354

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The Everest ransomware group is a medium-sophisticated criminal threat actor primarily motivated by financial gain. They specialize in targeting organizations across various sectors for ransomware attacks, focusing on collecting sensitive data such as customer privacy information, financial records, and credit card details. Known for leaking stolen data on the darknet if their victims fail to pay ransoms, Everest poses a significant threat due to their ability to persistently target global organizations and their use of extortion tactics to maximize financial gains.

Goals & Targeting

The primary goal of the Everest group is to generate financial gain through ransomware attacks and the sale of stolen data. They target organizations across multiple sectors, including finance, healthcare, logistics, and technology, due to the high value of sensitive information in these industries. Their targeting profile indicates a preference for large or medium-sized enterprises that are likely to have significant amounts of valuable data and the financial capacity to pay ransoms. The group's strategic objective is to maximize their profit by combining immediate revenue from ransom payments with long-term gains through data monetization.

Enhanced Description

The Everest ransomware group is a cybercriminal organization known for its focus on collecting and analyzing sensitive data from victims. They primarily target organizations across various sectors, including finance, healthcare, logistics, and more, seeking to gain financial advantage through ransom payments and the sale of stolen information. The group has a history of leaking victim data on darknet marketplaces if their demands are not met, which adds additional pressure on targeted organizations. Everest's operational model involves conducting extensive data collection efforts, ensuring that their attacks result in significant data breaches with long-term consequences for victims. Their targeting strategy reflects a clear understanding of the value of sensitive information and the fear factor associated with public data exposure.

Key Capabilities

  • Data collection and analysis
  • Ransomware deployment
  • Data exfiltration
  • Darknet market exposure of stolen data
  • Persistent targeting of high-value organizations

MITRE ATT&CK Tactics

Espionage
Exfiltration
Ransomware Activity
Credential Access
Defense Evasion

ATT&CK Techniques

T1566.001
T1566.003
T1078
T1552
T1546

Software / Tooling

Custom ransomware
Network exfiltration tools
Darknet marketplace tools
Information theft utilities

Campaigns & Victims

Everest has been involved in numerous campaigns targeting organizations globally. Their operations include attacks on financial institutions, logistics companies, and healthcare providers, among others. Notable campaigns involve the Fiserv, Symcor, TSYS, and Epiq Global incidents, where they successfully exfiltrated large volumes of sensitive data. The group's operational tempo is characterized by methodical targeting, persistent data collection, and follow-up extortion efforts. Their victims frequently include high-profile organizations in sectors where data leakage would have severe reputational and financial impacts.

IOC Patterns

  • Spear-phishing campaigns targeting senior executives
  • Use of custom ransomware with encryption capabilities
  • Lateral movement within a network using compromised credentials
  • Data exfiltration via encrypted channels to external servers
  • Presence of known Everest-related file hashes or domains

Recommended Actions

  • Implement strong access controls and multi-factor authentication for sensitive systems.
  • Encrypt sensitive data at rest and in transit.
  • Monitor network traffic for signs of lateral movement and data exfiltration attempts.
  • Conduct regular backups of critical systems and isolate backup files from network access.
  • Train employees to recognize and report potential phishing attempts.
  • Establish a robust incident response plan to address potential ransomware incidents.

Suggested Tags

Ransomware
Financial-gain
Data-theft
Extortion
Darknet

Confidence Assessment

Moderate confidence in Everest's operational details, with some gaps remaining unclear. While their campaigns and targeting patterns are well-documented, specific technical tools and exact TTPs remain under partial disclosure. Organized crime groups like Everest often evolve quickly, making it essential for organizations to stay ahead of their tactics through continuous threat intelligence monitoring.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

208

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Ransomware
Financial-gain
Data-theft
Extortion
Darknet

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 9, 2021
Last Seen
Aug 4, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.