Everest Ransomware Group
Threat Actor
The Russian linked Everest group has been responsible for multiple ransomware attacks and data breaches since 2020. Since it surfaced in 2020, the Everest ransomware operation has switched tactics from data theft-only corporate extortion to including ransomware in its attacks to encrypt victims' compromised systems.
Notable victims of Everest ransomware attacks include the Brazilian Government, Coca-Cola, the U.S. space agency, NASA, and the cannabis retail chain, Stiiizy.
Incidents Associated with this Threat
- November 18, 2025: Ransomware Attack at Under Armour
- November 13, 2025: Catalyst RCM Attack Leads to Ransomware Hacks
- October 25, 2025: Databreach at Swedish Power Grid Operator Svenska kraftnät
- May 22, 2025: Ransomware Attack hit Coca-Cola’s Middle East Operations
Malware Used by this Threat Actor
No malware identified for this threat actor.
