Egregor ransomware group
Egregor is one of the extortion operations we watch continuously. This page covers what is known about the group and the current state of its leak site, which we last saw change 17h ago.
Who they are
Egregor is a ransomware strain that appeared in September 2020, widely believed to be a rebrand or successor to the Maze ransomware operation, using similar infrastructure and tactics. It runs as a Ransomware-as-a-Service (RaaS), recruiting affiliates to deploy its payload in exchange for a percentage of ransom payments. Egregor employs a double-extortion model, encrypting files with ChaCha and RSA-2048 algorithms, while exfiltrating sensitive data to threaten public release. Victims receive ransom notes directing them to Tor-based portals for negotiation. The group has targeted organizations worldwide across sectors such as retail, transportation, manufacturing, and finance, with notable attacks on Barnes & Noble and Cencosud. Egregor's operations were disrupted in early 2021 through coordinated law enforcement action, leading to the arrest of suspected affiliates in Ukraine.
Current status
Egregor's leak site is answering our checks. That does not mean the group is actively posting — plenty of sites stay up for months with nothing new on them — but the infrastructure is live.
The last change we recorded on it was 17h ago (4 Sep 2026 19:02 UTC).
Which organisations this group has named, and when, is part of the SINON platform rather than this page. Create an account to search it, or to be told automatically if a name you care about turns up.
Sectors targeted
This group does not state an industry on its site, so we have nothing reliable to report. Most crews are opportunistic rather than sector-specific in any case — they hit what they can reach.
Watching for your name
If Egregor posts your company, a supplier or a subsidiary, you want to hear it from us rather than from a journalist. SINON checks these sites continuously and alerts on the names you give it.
Start monitoring