Everest
Active Since
December 2020
Known Forum Aliases
N/A
Active Forum Accounts
N/A
Everest has been around since at least 2020, making it one of the oldest ransomware operations still active after LockBit and Cl0p.
Initially using the now-popular technique of double extortion – encrypting a victim’s data in addition to stealing and threatening to publish it on its dark web leaks site – Everest has claimed in recent years to eschew ransomware and engage in data extortion-only attacks. The gang has also been observed moonlighting as an initial access broker, providing unauthorized corporate network access to other threat actors for a fee.