Egregor Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
January 7, 2026
Last Seen
June 9, 2026

Egregor is a ransomware-as-a-service (RaaS) operation known for double extortion and a public leak site, functioning through a broad affiliate network to compromise and encrypt victim systems while exfiltrating data.

Overview

Egregor is a ransomware-as-a-service (RaaS) operation known for double extortion and a public leak site, functioning through a broad affiliate network to compromise and encrypt victim systems while exfiltrating data. It has been among the more prominent ransomware actors, driving significant impact across industries and drawing sustained attention from cyber defense communities.

Related Threat Clusters

Recent Intelligence Reports

  • New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
  • New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
  • T1685: Disable or Modify Tools — attack.mitre.org · April 28, 2026
  • Manager of botnet used in ransomware attacks gets 2 years in prison — Bleepingcomputer · March 25, 2026
  • New Veeam vulnerabilities expose backup servers to RCE attacks — Bleepingcomputer · January 7, 2026

CVSS v3.1 Breakdown