Back to Intelligence

EVEREST Ransomware Gang: 5 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules

SA
Security Arsenal Team
October 7, 2026
11 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-07 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

EVEREST Ransomware Gang: 5 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules

Executive Summary

Between 2026-10-05 and 2026-10-06, the EVEREST ransomware group listed five organizations on its dark web leak site: Kennametal (Manufacturing, US), Flydubai (Transportation, AE), B-accountants (Professional Services, NL), Morcon Developments (Other, country unspecified), and Agri Industrial (Agriculture and Food Production, country unspecified). All five postings were independently observed by two separate leak-site crawlers, which corroborates that the claims were made — it does not confirm any breach occurred.

Security teams at organizations in these sectors and geographies should treat this bulletin as an early-warning signal: EVEREST's historical playbook emphasizes phishing, exposed remote access, and abuse of valid accounts for initial access, followed by data exfiltration before encryption. The detection engineering content below is tuned to those behaviors, not to the unverified claims themselves.

Sourcing & Verification

  • Corroboration status: 5 of 5 listings in this dataset were independently observed by a second leak-site crawler; 0 appear on a single source only. Multi-source observation confirms the gang published the claim; it does not confirm a compromise.
  • Inclusion reflects the threat actor's claim and is NOT confirmation of a breach. A leak-site posting is an accusation made by a criminal organization, frequently used as an extortion pressure tactic. No tier in our data confirms a breach — only the named organization or its regulator can do that.
  • A named organization may dispute the listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question either way.
  • Corrections: Security Arsenal will publish corrections and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — EVEREST

Aliases / naming: Also tracked as EVEREST Group; historically linked to the wider BlackByte/Everest ecosystem and has at times operated as an initial access broker (IAB), selling network access to other actors in addition to running its own extortion operations.

Operational model: EVEREST runs a hybrid operation — it recruits affiliates in a RaaS-like arrangement but maintains tight control over leak-site publication and negotiation. It has historically tolerated a smaller, more selective affiliate pool than mass-market families like LockBit, which aligns with its comparatively low posting volume (5 listings in the last 100-post observation window is consistent with a deliberate, targeted cadence).

Extortion model: Double extortion is standard. Victims are listed on the Tor-based leak site with a countdown timer; if the deadline passes, data is either leaked incrementally or (in past incidents) the gang has advertised the stolen data for sale to third parties — an escalation step many groups claim but fewer actually execute.

Typical ransom demands: Historically in the low-to-mid seven-figure range for mid-market victims, scaling with perceived revenue. The gang is known to be negotiable and has accepted partial payments for delayed publication in the past.

Known initial access methods:

  • Spear phishing with macro-enabled Office attachments or ISO/LNK container files
  • Compromised or brute-forced RDP endpoints exposed to the internet
  • Valid accounts purchased from access brokers (VPN concentrators, legacy Citrix)
  • Exploitation of perimeter appliances (firewalls, remote access gateways)

Dwell time: Historically short-to-moderate — typically 3–10 days between initial access and encryption, with exfiltration usually occurring 24–72 hours before detonation. The pre-encryption window is where detection has the highest value.

Current Campaign Analysis

Sectors being targeted

The five listings span Manufacturing, Transportation, Professional Services, Agriculture and Food Production, and an uncategorized "Other." This is broad rather than sector-focused, but manufacturing remains the single most common EVEREST target across its history — consistent with the sector's low tolerance for downtime and high pressure to pay. The appearance of an accounting/professional services firm (B-accountants) is notable: accountancy firms aggregate sensitive financial data from many downstream clients, making them high-leverage extortion targets.

Geographic concentration

Confirmed geographies are the United States, United Arab Emirates, and the Netherlands, with two listings lacking a stated country. The UAE listing (Flydubai) reflects EVEREST's longstanding willingness to operate outside the Western European/North American core — a differentiator from groups that avoid Middle East targets.

Victim profile

The set mixes large enterprises (a multinational manufacturing firm, a regional airline) with smaller professional services and agricultural firms. Estimated revenue range spans roughly tens of millions to several billion USD. This spread suggests EVEREST is not running a size-gated campaign — it is monetizing whatever access its affiliates and broker channels deliver.

Posting frequency and escalation patterns

Four of the five listings were published on a single day (2026-10-06), with the fifth (Agri Industrial) on 2026-10-05. Burst-posting is a known EVEREST pattern: the gang often lists several victims simultaneously to create the appearance of scale and pressure laggard negotiators. Watch for a follow-on wave 7–14 days out, which historically accompanies countdown expirations.

CVE exposure hypothesis

We have no evidence linking any specific CVE to any named listing above. However, EVEREST's documented reliance on perimeter exploitation and stolen credentials makes the following CISA KEV entries (all with confirmed ransomware use) relevant as sector-level exposure hypotheses worth auditing against immediately:

  • CVE-2026-59310 (VMware vCenter path traversal) — vCenter compromise maps directly to EVEREST's known interest in hypervisor-level encryption.
  • CVE-2026-50751 (Check Point Security Gateway improper authentication) and CVE-2026-20316 (Cisco FMC hard-coded password) — both match the gang's perimeter-appliance initial access pattern.
  • CVE-2026-63077 (JetBrains TeamCity deserialization) — CI/CD server compromise provides lateral movement and code-signing access, a documented pre-ransomware staging foothold.
  • CVE-2026-48027 (Nx Console embedded malicious code) — a supply-chain vector consistent with developer-workstation entry points.

Treat these as patch-priority drivers, not attribution.

Detection Engineering

The following rules target EVEREST's documented TTPs: remote-access initial access, macro/phishing execution, lateral movement via PsExec/WMI/Cobalt Strike, and pre-encryption data staging.

YAML
---
title: EVEREST - Suspicious Macro-Enabled Document Spawning Script Interpreter
id: 8f2c1a10-e7b4-4d2a-9c11-4a2b8d1e0001
status: experimental
description: Detects Office applications spawning script interpreters or LOLBins, consistent with EVEREST phishing-macro initial access chains.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
  service: security
detection:
  selection_parent:
    ParentImage|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\outlook.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\certutil.exe'
  condition: selection_parent and selection_child
fields:
  - CommandLine
  - ParentCommandLine
  - User
level: high
tags:
  - attack.execution
  - attack.t1204.002
  - attack.t1059
date: 2026/10/07
---
title: EVEREST - Lateral Movement via PsExec Service or WMI Remote Process
id: 8f2c1a10-e7b4-4d2a-9c11-4a2b8d1e0002
status: experimental
description: Detects PsExec-style service installation and WMI remote process creation, both used by EVEREST for lateral movement prior to encryption.
author: Security Arsenal Threat Intelligence
logsource:
  product: windows
  service: system
  definition: 'EventID 7045 service installation'
detection:
  psexec_service:
    EventID: 7045
    ServiceFileName|contains:
      - 'PSEXESVC'
      - '\ADMIN$\'
  wmi_remote:
    EventID: 4688
    ParentImage|endswith: '\WmiPrvSE.exe'
    CommandLine|contains:
      - 'cmd.exe /c'
      - 'powershell'
      - '\\'
  condition: psexec_service or wmi_remote
fields:
  - ServiceName
  - ServiceFileName
  - CommandLine
  - Computer
level: high
tags:
  - attack.lateral-movement
  - attack.t1569.002
  - attack.t1021.002
  - attack.t1047
date: 2026/10/07
---
title: EVEREST - Pre-Encryption Staging - Shadow Copy Deletion and Mass Exfil Tooling
id: 8f2c1a10-e7b4-4d2a-9c11-4a2b8d1e0003
status: experimental
description: Detects Volume Shadow Copy deletion and known exfiltration/archiving tooling (rclone, 7zip with password) consistent with EVEREST pre-detonation staging.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  shadow_delete:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
      - '\wbadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'recoveryenabled no'
      - 'delete catalog'
  exfil_tools:
    Image|endswith:
      - '\rclone.exe'
      - '\7z.exe'
      - '\winscp.exe'
      - '\filezilla.exe'
    CommandLine|contains:
      - ' -p'
      - ' copy '
      - ' sync '
      - ' mega'
      - ' anonfiles'
  condition: shadow_delete or exfil_tools
fields:
  - CommandLine
  - ParentImage
  - User
  - Computer
level: critical
tags:
  - attack.impact
  - attack.t1490
  - attack.exfiltration
  - attack.t1567
date: 2026/10/07

The Sentinel query below hunts for the lateral-movement-to-staging handoff EVEREST exhibits: remote session establishment followed by archive/exfil tooling within a 72-hour window.

KQL — Microsoft Sentinel / Defender
// EVEREST hunt: RDP/WinRM session -> staging tooling within 72h
let stagingTools = dynamic(["rclone", "7z.exe", "winscp", "filezilla", "psexec", "megasync"]);
let remoteSessions =
    DeviceLogonEvents
    | where TimeGenerated > ago(14d)
    | where LogonType in ("RemoteInteractive", "Network")
    | where InitiatingProcessRemoteIPType == "Public"
    | summarize FirstRemoteAccess=min(TimeGenerated), RemoteIPs=make_set(InitiatingProcessRemoteIP)
        by DeviceName, AccountName;
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName has_any (stagingTools) or ProcessCommandLine has_any (stagingTools)
| join kind=inner remoteSessions on DeviceName
| where TimeGenerated between (FirstRemoteAccess .. FirstRemoteAccess + 72h)
| project DeviceName, AccountName, FirstRemoteAccess, RemoteIPs,
          StagingTime=TimeGenerated, FileName, ProcessCommandLine, FolderPath
| sort by FirstRemoteAccess asc;

Run this PowerShell as an administrator on internet-facing servers and domain controllers to enumerate the pre-ransomware artifacts EVEREST leaves behind: new scheduled tasks, recent shadow-copy tampering, and exposed RDP configuration.

PowerShell
# Security Arsenal — EVEREST Rapid Triage (run as admin)
Write-Host "=== [1] Scheduled tasks created in last 7 days ==="
Get-ScheduledTask | Where-Object {
    (Get-ScheduledTaskInfo $_).LastRunTime -gt (Get-Date).AddDays(-7)
} | Select-Object TaskName, TaskPath, @{n='Action';e={$_.Actions.Execute}} | Format-List

Write-Host "=== [2] Volume Shadow Copy status ==="
vssadmin list shadows
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7036; StartTime=(Get-Date).AddDays(-3)} -ErrorAction SilentlyContinue |
    Where-Object { $_.Message -match 'VSS|Volume Shadow Copy' } |
    Select-Object TimeCreated, Message | Format-List

Write-Host "=== [3] RDP exposure check ==="
$rdp = Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections
Write-Host "RDP enabled: $(-not [bool]$rdp.fDenyTSConnections)"
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue |
    Select-Object LocalAddress, LocalPort, OwningProcess
$nla = Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication
Write-Host "NLA required: $($nla.UserAuthentication)"

Write-Host "=== [4] New local admins in last 14 days ==="
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4732,4728; StartTime=(Get-Date).AddDays(-14)} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, Id, Message | Format-List

Incident Response Priorities

T-minus detection checklist (before encryption fires)

EVEREST's short dwell time means the pre-detonation window is narrow. In priority order:

  1. Shadow copy deletion / recovery disabling (vssadmin delete shadows, bcdedit recoveryenabled no) — the single highest-fidelity signal that encryption is imminent.
  2. New archive/exfil tooling on servers: rclone, 7-Zip with password flags, WinSCP, MEGAsync.
  3. Mass file enumeration (adfind, net.exe group queries, BloodHound/SharpHound collection) from a single workstation.
  4. PsExec service artifacts (PSEXESVC in ADMIN$) or WMI remote execution fanning out from one host.
  5. Unusual outbound data volume from file servers or databases in the prior 72 hours — EVEREST exfiltrates before it encrypts.
  6. EDR tampering events — disabled sensors, deleted logs, or new exclusions pushed via GPO.

Critical assets EVEREST historically prioritizes for exfiltration

  • Finance and accounting data (payroll, tax filings, client ledgers — especially relevant given the B-accountants listing)
  • Contracts, M&A documents, and legal correspondence
  • HR records with PII (used as secondary extortion leverage against employees)
  • Engineering/IP repositories in manufacturing victims (drawings, process documentation)
  • Email archives of executive leadership

Containment actions ordered by urgency

  1. Isolate affected hosts at the switch/EDR level — do NOT power off (preserves memory and running encryption keys).
  2. Disable the compromised accounts and force enterprise-wide credential resets, prioritizing privileged and service accounts.
  3. Block egress to known exfil destinations (rclone endpoints, anonymous file-sharing services) at the proxy/firewall.
  4. Snapshot and isolate the backup infrastructure; verify offline/immutable copies exist before attackers reach them.
  5. Take vCenter/hypervisor management offline if ANY vCenter compromise indicator exists — EVEREST targets hypervisors for maximum blast radius.
  6. Engage legal counsel on disclosure obligations before any negotiation; a leak-site listing alone does not establish reportability, but regulatory clocks may start on confirmation.

Hardening Recommendations

Immediate (24 hours)

  • Patch or mitigate the CISA KEV entries above, prioritizing CVE-2026-59310 (vCenter), CVE-2026-50751 (Check Point), and CVE-2026-20316 (Cisco FMC) — these map directly to EVEREST's initial access and hypervisor-targeting patterns.
  • Disable Office macros by default via GPO and block ISO/LNK container execution from email attachments.
  • Audit all externally exposed RDP; place any required RDP behind VPN with MFA and enable NLA.
  • Enforce phishing-resistant MFA (FIDO2) on all VPN, remote access, and OWA endpoints — EVEREST heavily uses valid accounts.
  • Deploy the detection rules above and alert on shadow-copy deletion as a page-the-SOC critical event.

Short-term (2 weeks)

  • Segment hypervisor management networks away from user and server VLANs; require jump-box access with session recording.
  • Move to immutable/offline backup architecture (object-lock or air-gapped) and test restoration — EVEREST's 3–10 day dwell time means backups are often found and targeted.
  • Implement application allowlisting (WDAC/AppLocker) on file servers and domain controllers to break the PsExec/LOLBins lateral movement chain.
  • Deploy egress filtering with TLS inspection to catch exfiltration to file-sharing and cloud storage services not in your approved inventory.
  • Establish dark web monitoring for your organization, subsidiaries, and key suppliers so a leak-site listing reaches you within hours, not days.

All victim names in this briefing reflect claims published by the EVEREST group on its leak site and independently observed by two crawlers. None of the listings constitute confirmation of a breach. Organizations named here may contact Security Arsenal at security@securityarsenal.com.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.