Skip to content
Everest Ransomware

Everest Ransomware

www.provendata.com July 24, 2026

Everest is a financially motivated ransomware and cyber extortion group active since at least December 2020. Over five years of activity, Everest has combined ransomware deployment, data-leak extortion, initial-access brokerage, and direct insider recruitment into a single, adaptable criminal operation that has proven resilient to infrastructure disruptions and law enforcement pressure.

As of July 20, 2026, the Everest ransomware group had publicly claimed 365 victims on its leak site, including 0 in the last 30 days. Known victims are concentrated in Healthcare (17%), Business Services (15%) and Technology (12%), and span 35 countries.

This summary is automatically pulled from live cyber threat feeds. Because threat data changes rapidly, please verify critical details manually before taking action. Figures reflect publicly-claimed leak-site victims, not total infections.

The group has compromised or claimed attacks against organizations across healthcare, aerospace, government, aviation, and critical infrastructure, with victims spanning North America, Latin America, and Europe.

Few ransomware groups have reinvented their operational model as deliberately as Everest. Over five years, the group moved from a data-theft-only operation to full double extortion, then pivoted toward access brokerage and insider recruitment as conditions in the criminal ecosystem shifted.

Understanding that progression matters for defenders: the tactics Everest uses today are a product of calculated adaptation, not a fixed playbook.

Everest emerged in December 2020 as a data theft and extortion operation. Early campaigns focused on network compromise, data exfiltration, and leak-site publication without deploying file-encrypting malware.

Initial targeting was concentrated in Canada, Latin America, and the public sector. Researchers noted early operational similarities to the EverBe 2.0 ransomware lineage, which informed later encryption design choices.

Encryption routines used AES and DES algorithms, with a notable architectural decision: encryption keys were generated locally on victim hosts rather than delivered from a remote command-and-control server. This reduced dependency on centralized infrastructure and complicated decryption-key-based recovery approaches that assume server-side key custody.

The standard attack sequence became: initial compromise → reconnaissance → data exfiltration → encryption → public extortion via leak site.

Beginning around November 2021, HC3 reporting from the U.S. Department of Health and Human Services identified Everest operating as an initial access broker (IAB), selling compromised network footholds to other cybercriminal actors rather than always deploying ransomware directly.

This repositioned Everest simultaneously as a direct threat actor and a supplier to other criminal ecosystems , a materially different risk profile than a conventional ransomware group, and one that makes disrupting any single operation less effective.

In October 2023, Everest began openly recruiting corporate insiders through cybercrime forums, advertising for employees willing to provide VPN access, IT administrators, and contractors with privileged credentials. Compensation offers included cash payments and revenue-sharing arrangements drawn from extortion proceeds.

When an attacker can recruit a legitimate employee, multi-factor authentication becomes less effective, and detection shifts from perimeter monitoring toward behavioral analysis of accounts that have every right to be where they are.

Recent reports indicate the group increasingly favors data-only extortion, bypassing encryption entirely in favor of faster, lower-footprint monetization. This trend likely reflects growing law enforcement pressure on traditional ransomware models and a preference for reduced forensic exposure.

In 2025, Everest's dark web leak site was defaced with the message "Don't do crime CRIME IS BAD xoxo from Prague." Security researchers speculated the defacement may have involved rival operators. Despite the disruption, the group continued operations, a pattern consistent across infrastructure setbacks.

Not every Everest incident follows the same pattern. Some operations focus exclusively on data theft and extortion without deploying encryption. The following phases reflect the group's full-capability attack chain.

Everest's primary entry point is through exposed remote services, including Remote Desktop Protocol (RDP) and VPN endpoints.

Additional access vectors include:

Once inside, operators enumerate the environment: Active Directory discovery, network mapping, file identification, backup location, and administrative privilege assessment.

Observed tooling includes SoftPerfect Network Scanner alongside built-in Windows utilities and PowerShell.

Backup identification is a deliberate early-phase priority; locating and later disrupting recovery options before the victim detects the intrusion is central to the group's pressure strategy.

Credential harvesting typically involves using ProcDump to dump LSASS memory and extract credentials from the Windows process that manages authentication.

Harvested credentials enable subsequent lateral movement without triggering new authentication events, and support privilege escalation toward domain-level access.

Everest relies heavily on legitimate administrative tools to blend with normal enterprise activity, a technique commonly referred to as living off the land . Observed tools include AnyDesk, Splashtop, Atera, RDP, SMB, and PowerShell remoting. These tools behavioral signatures with legitimate IT operations, which is precisely why they are selected.

According to Proven Data’s expert Amr Fathy, WMI and PowerShell are the most common lateral movement tools. The commands look identical to those used in sysadmin activity. “We differentiate by context: which account, which time, which source, which child processes. WMI spawning certutil, for example,” he explains.

This behavioral differentiation, not signature detection, is the operative detection approach when legitimate tools constitute the primary threat.

Data exfiltration precedes encryption in Everest operations, and in data-only attacks, it is the entire operation.

Targeted data includes PII, PHI, financial records, legal documents, internal communications, intellectual property, and customer databases .

Staging relies on WinRAR and archive compression utilities, with exfiltration conducted over encrypted outbound channels that blend with normal web traffic.

When encryption is deployed, the ransomware appends .EVEREST to encrypted files and drops EVEREST LOCKER.txt as the ransom note.

Healthcare victims have reportedly received compressed extortion timelines designed to amplify operational pressure on environments with low downtime tolerance.

Across all incident types, victims face leak-site publication, countdown timers, and incremental sample data releases as escalating pressure mechanisms.

The following toolset reflects Everest's documented approach:

A defining behavioral pattern is the systematic post-execution deletion of tools, removing forensic artifacts after each operational phase to impede the reconstruction of the attack chain. This is paired with log tampering and temporary payload staging that leave minimal indicators once the operator has moved on.

Code analysis of Everest's encryption implementation links it to the BlackByte ransomware family and the EverBe 2.0 lineage. The local key generation design described earlier is one artifact of that lineage. Code overlap does not necessarily indicate a direct organizational relationship, but it does suggest shared development resources or code sourcing from overlapping criminal communities.

A broader evasion technique increasingly observed in ransomware operations is BYOVD (Bring Your Own Vulnerable Driver). "Attackers load a signed but vulnerable driver into kernel mode. Once there, they exploit it to terminate EDR processes and remove kernel callbacks. Some ransomware families now embed the vulnerable driver directly in the payload; the driver loads, EDR goes blind, encryption begins within seconds," explains Fathy

Everest has targeted organizations across healthcare, government, manufacturing, financial services, aerospace, transportation, critical infrastructure, telecommunications, energy, legal services, and education.

The HC3 unit within the U.S. Department of Health and Human Services issued a formal threat profile on Everest, identifying the group as a credible and growing risk to healthcare organizations. Specific risks include PHI exposure, disruption to surgical facilities, impacts on patient care, and HIPAA-related regulatory exposure.

The Ascension cyberattack established a clear precedent for how ransomware incidents translate into operational disruption at a healthcare scale. Healthcare remains a structurally attractive target due to its operational urgency, the value of PHI on criminal markets, limited tolerance for system downtime, and historically weaker network segmentation compared to the financial services or defense sectors.

For healthcare organizations evaluating their exposure, Proven Data's healthcare cybersecurity guide covers the specific controls and preparedness steps most relevant to this threat class.

The following incidents have been attributed to or claimed by Everest. Where claims remain publicly unverified, consistent with the broader pattern of ransomware leak-site postings, that status is noted.

Government and Public Sector

Aviation and Transportation

Aerospace and Defense

Critical Infrastructure

Everest has claimed incidents affecting European airport systems, Swedish power infrastructure, and telecommunications networks. Some of these claims have not been independently confirmed.

The following indicators are associated with Everest ransomware deployments, provided for detection and hunting purposes.

Greetings from the Everest team. Your systems have been attacked, the files are encrypted. You can read us in our blog (Tor browser needed)

Blog : ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad[.]onion

Or read our group in Twitter

Also, our team was able to bypass your "Dataprotection" as any other your protection software and more than 1 Terabyte of internal files were exfiltrated to our servers, which we can confirm with great joy and ease

The list contains financial documents, internal orders, KYC information(documents,photos...), trusted representatives personal info

Client risk levels,loans, debt and client data. Various financial documentation, backups , etc. etc.

The information was collected both from personal PCs and from centralized storage locations.

If an agreement is reached with us, this information will never be published and the problem will disappear as if it never happened, otherwise it will be posted on our blog and darknet. Which will lead to even greater financial and reputational losses on your part.

1.Attack logbook (months of experience with your company) with full list of vulnerabilities and bypass methods

2.Advices how to singifically improve your security and avoid such attacks in the future

3.We will delete all files from your company

4.We will attack your company no more

Yours trully Everest Team

Email to : [email protected]

Understanding how to respond to an Everest incident is as operationally important as understanding how the group operates. Proven Data's guide on how to handle a ransomware attack covers the broader response framework. The following priorities are specific to Everest's tradecraft.

The quality of the forensic record determines how much of the incident can ultimately be reconstructed.

Everest operators embed persistence in locations that survive standard recovery workflows.

Fathy notes that attackers embed persistence where teams don't check during recovery: a weekly task that re-downloads a beacon, or a modified GPO that pushes malicious logon scripts. “We've seen clients recover successfully and get re-compromised within 48 hours from a poisoned GPO in their restored Active Directory backup."

Before any environment is declared clean, audit scheduled tasks, logon scripts, GPO configurations, AdminSDHolder ACL modifications, application registrations in Entra ID, and service configurations.

Do not restore Active Directory backups without validating them against pre-incident snapshots.

Rotate credentials globally, not only for accounts that show direct compromise indicators.

In Everest incidents, credential exposure is typically broader than initial forensics suggest, because harvested credentials are used across multiple systems before any visible alert triggers.

Organizations requiring structured DFIR support or pre-incident preparedness can engage Proven Data's Incident Response Retainer for pre-negotiated access to response capabilities.

Everest represents the maturation of ransomware into a diversified cybercriminal enterprise. The group has cycled through four distinct operational models in five years: pure data extortion, double extortion with encryption, initial access brokerage, and insider-enabled data-only operations, with each transition improving operational resilience and revenue diversification.

For security teams, incident responders, and MSPs, the practical implication is that Everest incidents cannot be addressed solely by perimeter controls. Detecting this group requires behavioral analysis, identity monitoring, and post-compromise forensic capabilities in environments where the attacker may have operated undetected for weeks before triggering a visible alert.

Cybersecurity writer at Proven Data covering ransomware trends, incident response, and data protection best practices.

Amr Fathy is a dedicated cybersecurity professional with over 7 years of extensive experience in digital forensics, incident response, reverse engineering, and threat intelligence. He currently serves as Senior DFIR Engineer at Proven Data LLC, conducting triage collection, incident response, and digital forensics activities.

Content strategist at Proven Data focused on cybersecurity education, threat analysis, and ransomware awareness.

SETTRA Ransomware: Emerging Double-Extortion Threat

RansomHub Ransomware: Attack Chain, IOCs, and Incident Response Guide

How To Preserve Ransomware Evidence: A Step-By-Step Forensic Guide

WannaCry Ransomware: Attack Lifecycle And Incident Response Guide

MDR vs EDR: A Technical Guide For MSPS And IT Decision-Makers

Payload Ransomware: Variant Analysis, TTP Breakdown & Incident Response Playbook