Skip to main content
Mallory
1 malware family

Everest

Also known aseverestEverest Ransomwareeverest_groupeverest_ransomware_groupeverest_team

Everest is a ransomware-as-a-service (RaaS) operation active since at least 2020 and described in the content as Russia-linked. It is referred to as Everest, Everest Group, Everest gang, and Everest ransomware group/team. The content states that Everest uses a double-extortion model, stealing data, encrypting systems, and threatening publication if victims do not pay, and that it has also expanded into initial access brokerage by selling network footholds to other threat actors. The reporting ties Everest to repeated dark web leak-site extortion activity and victim claims across multiple sectors, including finance, insurance, automotive, aerospace, retail, healthcare, aviation, and manufacturing. Victims or claimed victims mentioned in the content include Frost Bank, Citizens Financial Group, Liberty Mutual, Under Armour, Iberia and Air Miles España, a file-transfer service provider supporting Nissan and Infiniti dealerships in North America, Collins Aerospace, Allegis Group, BMW, and incidents affecting Vikor Scientific/Vanta Diagnostics and affiliated labs via Catalyst RCM. The content also notes an Everest attack targeting a South Korean elevator manufacturer. Specific activity described includes Everest listing Frost Bank and Citizens Financial Group on its leak site on April 20 and giving a six-day deadline before release; claiming approximately 250,000 Frost Bank records and approximately 3.4 million Citizens records; claiming to have exfiltrated 250,000 Social Security numbers from Frost Bank; beginning to leak more than 108 GB of allegedly stolen Liberty Mutual data on May 4, 2026 after claiming the data was taken on April 30; claiming a 343 GB Under Armour breach in November 2025; claiming a 596 GB Iberia breach plus 430 GB of booking-related mail files; and claiming a 910 GB breach of a vendor file-transfer system used by Nissan and Infiniti dealerships. The content explicitly characterizes Everest as known for double-extortion tactics. It also states that Everest has amassed well over 100 victims across multiple sectors over the course of a year. In addition to victim operations, Everest itself was reportedly exposed by 0APT, which leaked hashed and encoded publication and user information, and the same defacement message later seen in the LockBit panel compromise was previously used in a compromise of Everest’s dark web leak site. The content notes Everest had not launched a counterattack against 0APT at the time of reporting.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics21 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589×2
Gather Victim Identity Information
TA0001
Initial Access
3 techniques
T1078×4
Valid Accounts
T1133
External Remote Services
T1195×2
Supply Chain Compromise
TA0003
Persistence
2 techniques
T1078×4
Valid Accounts
T1133
External Remote Services
TA0004
Privilege Escalation
1 technique
T1078×4
Valid Accounts
TA0005
Stealth
1 technique
T1078×4
Valid Accounts
TA0009
Collection
1 technique
T1213×4
Data from Information Repositories
TA0010
Exfiltration
5 techniques
T1020×4
Automated Exfiltration
T1041×9
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
T1537×3
Transfer Data to Cloud Account
T1567×5
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
5 techniques
T1486×12
Data Encrypted for Impact
T1489
Service Stop
T1499
Endpoint Denial of Service
T1565
Data Manipulation
T1657×4
Financial Theft
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

IOCS

Observables

3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping17

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables3

Domains, IPs, and hashes tied to this actor, refreshed continuously.