ZeroHour

everest

ransomware group · aka Everest, EVEREST, Everest ransomware group · unknown · active since late 2024, per public ransomware trackers and vendor research (Cyberint/Check Point described it as newly emerged in early-2025 reporting); exact first-seen date unknown

Victims · 7d
0▼4
Victims · 30d
12active targets
Victims · 90d
34
All-time (tracked)
503since 2021-09-09
Last post
09-07 17:26UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Everest is a ransomware and data-extortion group that emerged in late 2024 and operates as a ransomware-as-a-service (RaaS) brand, reportedly recruiting affiliates on underground forums including RAMP, per Cyberint/Check Point research (2025). It uses double extortion - stealing data and encrypting systems - and is notable for publicly marketing a 'no-leak' pledge, claiming it deletes stolen data and provides proof of deletion after payment rather than reselling or publishing it (vendor reporting, 2025). The group runs a Tor leak site where it names victims; attribution and national origin remain unknown, and no law-enforcement action against it has been publicly announced. Dashboard tracking shows low-volume, intermittent leak-site activity: 4 posts total since 2026-09-04, most recently 2026-09-07. Everest was cited in 2025-26 regional threat coverage discussing Qatar's threat landscape, and it should not be confused with a distinct older Everest-named file-encrypting strain documented around 2020.

Tactics & tooling
  • Double extortion: exfiltrates victim data and deploys encryption, threatening publication on its Tor leak site
  • RaaS model: advertises for affiliates on underground forums, including RAMP, per Cyberint/Check Point research (2025); affiliate infrastructure attribution largely unknown
  • 'No-leak' payment pledge: publicly claims stolen data will be deleted, with proof of deletion provided after ransom payment, rather than leaked or resold (per Cyberint/Check Point, 2025)
  • Victim shaming via leak-site posts naming targeted organizations; observed posting cadence is low-volume and intermittent (dashboard tracking, 2026)
  • Initial-access tradecraft not comprehensively documented in public reporting; no specific CVE exploitation or access-broker purchases publicly confirmed - unknown as of the dashboard period
Targeted sectors
manufacturing/engineeringtechnologylife sciences/biotech
Notable public victims

Koerber (KUERBER) - German international technology/engineering group, publicly listed on Everest's leak site per dashboard tracking (September 2026), GGS - publicly named on Everest's leak site per dashboard tracking; sector and details unknown, GeneSilico - publicly named on Everest's leak site per dashboard tracking; life-sciences/biotech; details unknown, Negotiation Rules - listed by this dashboard among recent posts; likely the group's posted negotiation-rules entry rather than a victim organization, a common leak-site practice - unconfirmed

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Balance Diagnostics · May 6, 2025
Jamjoom Pharma · May 2, 2025
Jordan Kuwait Bank · May 2, 2025
The Hoff Brand SL Data Leak · Apr 2, 2025More than 630,000 customers data and orders63GB internal documents and filesComplete email pst database CEO:Fran Marchena CEO | Founder [email protected]://thehoffbrand.comDownload:https://dropmefiles.com.ua/ua/2ZNKDVefBhttps://gofile.io/d/uzJxeh
Genie Healthcare Data Leak · Mar 26, 2025Database including the entire history of employee records and personal data!More than 4,400 personal IDs.Total amount of stolen data : 110GBhttps://geniehealthcare.com/Download:https://gofile.io/d/Tp0FPPhttps://dropmefiles.com.ua/ua/f4A9Y7https://dropmefiles.com.ua/ua/PHNhweS96
STIIIZY Full Data Leak · Feb 12, 2025Client’s Personal data and ID’s Total personal records : 422,075 https://www.stiiizy.com Download:https://gofile.io/d/zNW1O5https://gofile.io/d/d6W1n3https://gofile.io/d/Cdjchthttps://gofile.io/d/sSEvANhttps://gofile.io/d/nZDZjJhttps://gofile.io/d/CbAr30https://gofile.io/d/qs1eDU RAR password:pati63359.zipT$dkkuygtd68-kuhde4stiiizymodesto.zipo8uhu-GYI6r-5e4$T789f94885.zipHEtfd5ug7#45y-jyyfgGstiiizymission.zipv6tG-fdgrd@-hggfSfe3folder.zip4d5yfugy65d67hytrASWauthenticalameda.zip&Vibyf-u6rtEESt4dy.1-100000.zipu6fu6r-6r6-tjdjdH100001-190000.zipu6fu6r-6r6-tjdjdH1docs:1-30.zip30-50.zip50-150.zip150-160.zip165-185.zip160-165.zip185-190.zipaccount data.zipfchtd-EWed456-Sdc
C2S Technologies Inc. · Feb 4, 2025https://c2stechs.com Company representative should follow the instructions to contact us before time runs out
ITSS · Feb 4, 2025The ITSS GLOBAL internal network was attacked by our group. During the incident, more than 173 GB of internal important data were exfiltrated to our servers, including internal and confidential banking information, as well as contract information. Company representative should follow the instructions to contact us before time runs outhttps://www.itssglobal.com
Evidn Data Leak · Feb 3, 2025https://gofile.io/d/4iMCqe
Weeks, Brucker & Coleman, Ltd | Legal Services · Jan 27, 2025Weeks, Brucker & Coleman, Ltd internal network was attacked by our group. During the incident, more than 150GB of internal important data were exfiltrated to our servers, including internal and confidential information https://www.weeksbrucker.com/
Solaris-pharma.com leakage · Jan 21, 2025Full data publication
Solaris Pharma proof · Jan 16, 2025Company must enter the chat before the end of Monday; after the timer expires, more than 400 GB of internal data will be published Proof of stolen data: http://2vqamwfdpis5rkjtpkutigykp56n6hkxfurm6qukdxp6uz5uff5kkaid.onion/solaris-pharma/proof/
The Hoff Brand SL · Jan 16, 2025Total volume data :More than 630,000 customers data and orders: Name,Email,Financial Status,Paid at,Fulfillment Status,Fulfilled at,Accepts Marketing,Currency,Subtotal,Shipping,Taxes,Total,Discount Code,Discount Amount,Shipping Method,Created at,Lineitem quantity,Lineitem name,Lineitem price,Lineitem compare at price,Lineitem sku,Lineitem requires shipping,Lineitem taxable,Lineitem fulfillment status,Billing Name,Billing Street,Billing Address1,Billing Address2,Billing Company,Billing City,Billing Zip,Billing Province,Billing Country,Billing Phone,Shipping Name,Shipping Street,Shipping Address1,Shipping Address2,Shipping Company,Shipping City,Shipping Zip,Shipping Province,Shipping Country,Shipping Phone,Notes,Note Attributes,Cancelled at,Payment Method,Payment […]
Woodlake · Jan 16, 2025EMRs,Test Results,Patient’s History,Patient’s private information,Billing information etc.Total volume data : 180GBCompany representative should follow the instructions to contact us before time runs outhttps://woodlakecenter.com
Volt Infrastructure · Jan 16, 2025The Volt Infrastructure internal network was attacked by our group. During the incident, more than 526 GB of internal important data were exfiltrated to our servers, including internal and confidential information, as well as contract informationCompany representative should follow the instructions to contact us before time runs outhttps://voltinfra.com
Solaris Pharma · Jan 14, 2025The Solaris Pharma internal network was attacked by our group. During the incident, more than 400 GB of internal important data were exfiltrated to our servers, including internal and confidential information, as well as contract information To restore access to files and prevent the publication of internal documents A company representative should contact us using […]
Welcomehallmission.com · Jan 13, 20252 TB of internal data are free to downloadLink:http://bifpwatchoxp7tsb2kpes37b23ogjrb2kj4wgr7yncf4hhgsfahu7jad.onion/welcomehall/
Evidn · Jan 11, 2025Total amount of stolen data : 50GBhttps://www.evidn.comCompany representative should follow the instructions to contact us before time runs out
Protected: Title Hidden · Jan 11, 2025There is no excerpt because this is a protected post.
Myhealthcarebilling Data Leak · Jan 9, 2025https://gofile.io/d/x0iEjw
Sarah Car Care Data Leak · Jan 9, 2025https://gofile.io/d/ZcxZCLhttps://dropmefiles.com.ua/ua/9MBWzXcG
Izmocars Data Leak · Jan 9, 2025https://gofile.io/d/DacgtL
CO-VER Power Technology SpA Data Leak · Jan 9, 2025Part1https://dropmefiles.com.ua/ua/3camURSQXhttps://dropmefiles.com.ua/ua/EDZLvcS
STIIIZY Happy New 20025 ! · Dec 25, 2024More gifts for STIIIZY are on the wayAt 10 pm, if the company does not contact us before by any method, we will post another 20025 customer’s personal data and ID records . UnMerry Christmas and UnHappy New Year
STIIIZY Pre-Christmas publication · Dec 23, 2024The first part of Christmas “gifts” for the company. If we continue to be ignored, the amount of published data will only grow. If you do not want to solve this problem with us, then we will cause many times more financial and reputational damage https://gofile.io/d/P7t7Y7https://dropmefiles.com.ua/ua/cyZe97
Genie Healthcare · Dec 20, 2024Database including the entire history of employee records and personal data!More than 4,400 personal IDs.Total amount of stolen data : 110GBhttps://geniehealthcare.com/Company representative should follow the instructions to contact us before time runs out
Izmocars · Dec 20, 2024Total volume data:More than 200GB of .msg files Files including:izmoltd izmocars izmolaw izmomedia izmolimited.com izmocars.be carazoosolutions.com auto-marketing.pro carazoo.com carsite.com cartalking.com citadeldefence.com citadelint.in citadelint.net cpa-marketing.pro deepheritage.com deepjansevasamiti.com dgipro.com dgipro-design.com digitalnanotechsg.com franchisenow.pro ipricecars.com izmocars.fr izmocrm.com izmodirect.com izmoeurope.be izmoinc.com izmolaw.com izmomedia.com izmonet.com izmostock.com izmostudio.com izmoweb.com izmoweb.in legal-marketing.pro partsgorilla.com smart-shiksha.com logixworld.com izmotion.com netmobyl.com si2microsystems.com vtcl.in sankeshwar.in medical-marketing.pro tejsoni.com motortrend.in […]
Bio-Clima Service Srl Data Leak · Dec 17, 2024https://bioclimaservice.it/ https://gofile.io/d/cLR5f7
Asaro Dental Aesthetics Data Leak · Dec 17, 2024Medical and personal data of 3800 patients https://asarodentalaesthetics.com https://gofile.io/d/4mnCIH
Total Patient Care LLC;A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of T · Dec 17, 2024https://gofile.io/d/XWQ7HJ
Artistic Family Dental;Value Dental Center;Sparkling Smiles Family Dentistry Data Leak · Dec 17, 2024https://gofile.io/d/NOUMwo
Myhealthcarebilling · Dec 13, 2024https://www.myhealthcarebilling.com/Company representative should follow the instructions to contact us before time runs out
Sarah Car Care · Dec 11, 2024Total amount of stolen data : 100GBhttps://sarahcarcare.com/Company representative should follow the instructions to contact us before time runs out
CO-VER Power Technology SpA · Dec 7, 2024Total amount of stolen data : 800GBhttps://www.co-ver.it/Company representative should follow the instructions to contact us before time runs out
Medical Technology Industries, Inc. · Dec 6, 2024Total amount of stolen data : 900GBhttps://mti.netCompany representative should follow the instructions to contact us before time runs out
STIIIZY · Nov 24, 2024Client’s Personal data and ID’s Total personal records : 422,075 https://www.stiiizy.com/ Company representative should follow the instructions to contact us before time runs out
Concord Orthopaedics · Nov 24, 2024Medical records and personal data of all patients from 2018 More than 30,000 identity documents https://www.concordortho.com/ Company representative should follow the instructions to contact us before time runs out
IndicaOnline · Nov 19, 2024Client’s Personal data and ID’s Total personal records : 422,075 https://indicaonline.com Company representative should follow the instructions to contact us before time runs out
Pacific Pulmonary Medical Group Data Leak · Nov 19, 2024https://gofile.io/d/fHjzi5 https://pacificpulm.com/
Total Patient Care LLC · Nov 15, 2024Medical records and personal information Company representative should follow the instructions to contact us before time runs out
A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of Texas Home Healthcare Se · Nov 15, 2024Medical records and personal information Company representative should follow the instructions to contact us before time runs out
Bio-Clima Service Srl · Nov 15, 2024https://bioclimaservice.it/Company representative should follow the instructions to contact us before time runs out
Pincu Barkan, Law Office and Notary · Nov 14, 2024More than 230,000 files including personal ID’s copies, fbi crime records, birth certificates etc. https://pincu-law.co.il/https://barkan-law.com/
Value Dental Center · Nov 13, 2024Medical and personal data of 5000 patients https://valuedentalcentercicero.com Company representative should follow the instructions to contact us before time runs out
Artistic Family Dental · Nov 13, 2024Medical and personal data of 5000 patients https://artisticfamilydental.comhttps://sparklingsmilesdentist.com Company representative should follow the instructions to contact us before time runs out
Asaro Dental Aesthetics · Nov 13, 2024Medical and personal data of 3800 patients https://asarodentalaesthetics.com Company representative should follow the instructions to contact us before time runs out
MedElite Group · Nov 8, 2024Medical and personal data of 119,000 patients https://medelitegrp.com Company representative should follow the instructions to contact us before time runs out
MCNA Dental Data Leak · Nov 1, 2024More than 1 million personal EMR’s https://gofile.io/d/yeIPm4 https://www.mcna.net/
Broward Realty Corp Data Leak · Nov 1, 2024https://gofile.io/d/XfRU15 2972 NW 60th St, Fort Lauderdale FL 33309Phone 954-645-7020 & 954-645-7733
CreaGen Inc Data Leak · Nov 1, 2024https://gofile.io/d/q7BB1q https://creageninc.com

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .