Everest — Ransomware Profile
Everest has been active since at least December 2020, opening with conventional double extortion and drifting toward theft-only extortion, where files are published or auctioned on its Tor leak site without the network necessarily being encrypted, according to RansomLook's profile of the brand. The site's copy advertises the data classes the operators treat as most saleable — customer records, financial detail, whole databases, payment-card numbers — and warns that anyone who stays silent gets published rather than quietly deleted; that is the group describing itself, not an independent account of what it actually holds. RansomLook also records a second line of business, with the operators reselling entry to networks they have already breached, which puts Everest closer to an access broker than to a pure encryption crew. Listed victims run through government, healthcare, manufacturing, professional services and IT across North America, Europe and Asia, and public trackers count several hundred postings over the operation's life. Claims against Nissan, Collins Aerospace and ASUS appear in both the Ransomware.live and RansomLook victim tables, though every leak-site entry stays an unverified assertion by the attacker until the named organisation confirms it.
IntelFusions coverage (2)
Tools & malware
Recent claimed victims
Vendor research
Read the full analysis on IntelFusions