Everest

Everest — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

EverestConfidence: High

Ransomware · incl. initial access brokerage

Motivation: Financial

11Attributed Breaches Circulating
HighAttribution Confidence
RansomwareActor Type

Overview

Evolved from ransomware and data extortion toward initial access brokerage and leak-based extortion, active since at least 2020. Healthcare-sector reporting links it to enterprise, healthcare, and industrial targeting; some reporting notes possible EverBe 2.0 and BlackByte links.

Tactics, Targeting & TTPs

Targeting: healthcare, enterprise, industrial. Possible links to EverBe 2.0 and BlackByte analysis in some reporting.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation