◇ SIGN IN
← all actors
ransomware

Everest

activemedium confidence
Ransomware
EverestEverest Ransom Team
Attribution
Financially motivated; hybrid ransomware + initial-access broker (unattributed)
Origin
Unknown (Russian-speaking operators assessed)
First seen
2020
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
UAE (and broader Gulf)
Sectors
Aviation, healthcare, government/tourism

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting UAE (and broader Gulf) (Aviation, healthcare, government/tourism sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Everest is a long-running extortion operation active since around 2020 that combines data-theft ransomware with initial-access brokering, and saw a resurgence targeting critical infrastructure in 2025.

History

Everest emerged around 2020 and operates a hybrid model, combining double-extortion ransomware with the sale of network access as an initial-access broker. It runs a darknet leak site and has listed 250+ victims since 2023 across many sectors. In April 2025 the group's leak site was hacked and defaced and went briefly offline, after which Everest resumed operations from new infrastructure.

The July-October 2025 window was reported as among Everest's most active periods, with claims against critical infrastructure including electricity transmission, aviation and telecommunications. Late in 2025 Everest publicized high-profile claims including Under Armour, Petrobras, and (in December 2025) ASUS, alleging over 1 TB of stolen data.

Everest has claimed victims in the UAE and elsewhere in the Gulf among its listings. These are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2025
Critical-infrastructure surge
Everest claimed attacks on electricity, aviation and telecom targets during its most active period (July-October 2025).
2025
Leak-site defacement
Everest's darknet site was defaced and went briefly offline in April 2025 before resuming on new infrastructure.
2025
Under Armour / Petrobras / ASUS claims
Everest publicized breaches of major brands including a December 2025 ASUS claim (claimed, not independently confirmed).

Claimed victims · 386 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
KeysightUSTechnology
PowerweaveINManufacturing
Mansfield Family DentistryUSHealthcare
Ingersoll RandUSManufacturing
OmnicellUSHealthcare
AptaraINProfessional Services
Al-Futtaim GroupUAERetail & E-Commerce
Alzone SoftwareTechnology
Dharma GroupITOther
Emirates Flight CateringUAEHospitality
Stadler RailCHTransportation
Rodschinson InvestmentBEFinancial Services