ZeroHour

everest

ransomware group · aka Everest, EVEREST, Everest ransomware group · unknown · active since late 2024, per public ransomware trackers and vendor research (Cyberint/Check Point described it as newly emerged in early-2025 reporting); exact first-seen date unknown

Victims · 7d
0▼4
Victims · 30d
12active targets
Victims · 90d
34
All-time (tracked)
503since 2021-09-09
Last post
09-07 17:26UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Everest is a ransomware and data-extortion group that emerged in late 2024 and operates as a ransomware-as-a-service (RaaS) brand, reportedly recruiting affiliates on underground forums including RAMP, per Cyberint/Check Point research (2025). It uses double extortion - stealing data and encrypting systems - and is notable for publicly marketing a 'no-leak' pledge, claiming it deletes stolen data and provides proof of deletion after payment rather than reselling or publishing it (vendor reporting, 2025). The group runs a Tor leak site where it names victims; attribution and national origin remain unknown, and no law-enforcement action against it has been publicly announced. Dashboard tracking shows low-volume, intermittent leak-site activity: 4 posts total since 2026-09-04, most recently 2026-09-07. Everest was cited in 2025-26 regional threat coverage discussing Qatar's threat landscape, and it should not be confused with a distinct older Everest-named file-encrypting strain documented around 2020.

Tactics & tooling
  • Double extortion: exfiltrates victim data and deploys encryption, threatening publication on its Tor leak site
  • RaaS model: advertises for affiliates on underground forums, including RAMP, per Cyberint/Check Point research (2025); affiliate infrastructure attribution largely unknown
  • 'No-leak' payment pledge: publicly claims stolen data will be deleted, with proof of deletion provided after ransom payment, rather than leaked or resold (per Cyberint/Check Point, 2025)
  • Victim shaming via leak-site posts naming targeted organizations; observed posting cadence is low-volume and intermittent (dashboard tracking, 2026)
  • Initial-access tradecraft not comprehensively documented in public reporting; no specific CVE exploitation or access-broker purchases publicly confirmed - unknown as of the dashboard period
Targeted sectors
manufacturing/engineeringtechnologylife sciences/biotech
Notable public victims

Koerber (KUERBER) - German international technology/engineering group, publicly listed on Everest's leak site per dashboard tracking (September 2026), GGS - publicly named on Everest's leak site per dashboard tracking; sector and details unknown, GeneSilico - publicly named on Everest's leak site per dashboard tracking; life-sciences/biotech; details unknown, Negotiation Rules - listed by this dashboard among recent posts; likely the group's posted negotiation-rules entry rather than a victim organization, a common leak-site practice - unconfirmed

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
National Money Mart Company · Nov 26, 2025
Petrobras Campos Basin 3D & 4D Seismic Survey Data - Database Leaked · Nov 25, 2025
Petrobras / SAExploration - Database Leaked · Nov 25, 2025
Iberia Airlines · Nov 25, 2025
FullBeauty Brands - Database Leaked · Nov 24, 2025
UNDER ARMOUR - Database Leaked · Nov 24, 2025
Air Miles España, S.A · Nov 24, 2025
AGFA - Database Leaked · Nov 23, 2025
KorPath - Database Leaked · Nov 23, 2025
Vikor Scientific, LLC / Korgene - Database Leaked · Nov 23, 2025
Streebo - Database Leaked · Nov 23, 2025
SIAD - Database Leaked · Nov 23, 2025
Petrobras Campos Basin 3D & 4D Seismic Survey Data · Nov 17, 2025
Petrobras / SAExploration · Nov 17, 2025
UNDER ARMOUR · Nov 17, 2025
Svenska kraftnät Database on sale for $2 Million · Nov 17, 2025
Svenska kraftnät 280GB Database on sale · Nov 17, 2025
FullBeauty Brands · Nov 13, 2025
Svenska Kraftnät data · Nov 13, 2025
Vikor Scientific, LLC / Korgene · Nov 13, 2025
KorPath · Nov 13, 2025
Dublin Airport - Database Leaked · Nov 11, 2025
Collins Aerospace / RTX.com - Database Leaked · Nov 11, 2025
SIAD · Nov 11, 2025
AGFA · Nov 11, 2025
Everest Exclusive Interview for Dailydarkweb.net · Nov 6, 2025
AT&T Careers - Database Leaked · Oct 28, 2025
Dublin Airport DataBase on sale for $1 Million · Oct 28, 2025
Air Arabia DataBase on sale for $2 Million · Oct 28, 2025
MotorsportMarkt.de · Oct 27, 2025
ANIA KRUK · Oct 27, 2025
Dublin Airport · Oct 26, 2025
Air Arabia · Oct 25, 2025
Svenska Kraftnät · Oct 25, 2025
AT&T Careers · Oct 22, 2025
Collins Aerospace Admits Responsibility for Flight Chaos at Heathrow, Brussels and Other M · Oct 19, 2025
Collins Aerospace / RTX.com · Oct 18, 2025
MUSE-INSECURE: Inside Collins Aerospaces Security Failure · Oct 18, 2025
Colins Aerospace / RTX.com · Oct 17, 2025
MUSE-INSECURE: Inside Colins Aerospaces Security Failure · Oct 17, 2025
Streebo · Oct 12, 2025
BMW · Sep 17, 2025
Professional Trust Company · Sep 15, 2025
MFO ITALIA · Sep 15, 2025
Key 4 Energy Srl · Sep 15, 2025
Studio Legale Tisot Iuris · Sep 15, 2025
Groupe Clarins · Sep 14, 2025
Everest file server · Sep 10, 2025
Allegis Group · Sep 10, 2025
Aupaircare and Intraxinc · Sep 10, 2025

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .