Egregor

S0554

Malware.View on attack.mitre.org

About this malware

Egregor is a Ransomware-as-a-Service (RaaS) tool that was first observed in September 2020. Researchers have noted code similarities between Egregor and Sekhmet ransomware, as well as Maze ransomware.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1027.002
Software Packing

Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.

T1033
System Owner/User Discovery

Egregor has used tools to gather information about users.

T1036.004
Masquerade Task or Service

Egregor has masqueraded the svchost.exe process to exfiltrate data.

T1039
Data from Network Shared Drive

Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel.

T1049
System Network Connections Discovery

Egregor can enumerate all connected drives.

T1055
Process Injection

Egregor can inject its payload into iexplore.exe process.

T1059.001
PowerShell

Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement.

T1059.003
Windows Command Shell

Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe.

T1069.002
Domain Groups

Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind.

T1071.001
Web Protocols

Egregor has communicated with its C2 servers via HTTPS protocol.

T1082
System Information Discovery

Egregor can perform a language check of the infected system and can query the CPU information (cupid).

T1105
Ingress Tool Transfer

Egregor has the ability to download files from its C2 server.

T1106
Native API

Egregor has used the Windows API to make detection more difficult.

T1124
System Time Discovery

Egregor contains functionality to query the local/system time.

T1140
Deobfuscate/Decode Files or Information

Egregor has been decrypted before execution.

View all 25 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Cyble Egregor Oct 2020 Open source
    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
  2. NHS Digital Egregor Nov 2020 Open source
    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
  3. Security Boulevard Egregor Oct 2020 Open source
    Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.