Everest Ransomware: Triple Threat of Encryption, Access, and Insiders

Umut Bayram | 7 MIN READ

| July 10, 2026

Key Takeaways

  • Everest is a Windows ransomware active since December 2020, running as a closed Russian-speaking group.
  • Three revenue streams combine ransomware deployment, initial access brokering since 2021, and paid insider recruitment since 2023.
  • Files are encrypted with locally generated AES-128-CBC keys, wrapped using an embedded RSA public key.
  • Before encryption, Everest deletes shadow copies and restore points, disables Controlled Folder Access, and removes an open-source anti-ransomware tool, Raccine.
  • The Picus Platform lets teams simulate Everest attacks and validate security controls against real-world techniques.

Everest is a Windows ransomware and data-extortion operation that has been active since December 2020, running as a closed group that also sells network access and recruits corporate insiders.

It encrypts files with the .everest extension, threatens victims with leaked data on a Tor-based leak site, and is technically linked to the BlackByte ransomware.

What sets Everest apart from single-purpose encryptors is its three-stream business model: ransomware deployment, initial access brokering (IAB) since November 2021, and paid insider recruitment since October 2023.

This post breaks down what Everest is, then walks through its execution flow stage by stage. At the end, we will show how Picus helps you validate your security controls against this threat.

Everest Ransomware at a Glance

Attribute

Detail

Emergence

December 2020

Malware type

Closed-group Ransomware-as-a-Service style operation with IAB and insider-recruitment side businesses

Platform / language

Windows; C# / .NET

Encryption scheme

AES-128-CBC, key wrapped with RSA

Encrypted extension

.everest

Ransom note

EVERESTRANSOMWARE.txt / EVEREST LOCKER .txt

Packing / obfuscation

ConfuserEx 1.x on .NET builds; UPX on native builds

Payment

Cryptocurrency, Monero (XMR) preferred over Bitcoin

Industries targeted

Healthcare, financial services, legal, construction, government, manufacturing, aviation, energy/utilities

Regions

United States (over one-third of victims), Europe, emerging Middle East

What is Everest Ransomware?

Everest is a Russian-speaking, closed-group ransomware operation that encrypts Windows hosts with the .everest extension while also operating as an initial access broker and running a paid corporate-insider recruitment program.

At its core, Everest runs three parallel revenue streams [1]:

  1. Ransomware deployment: Double-extortion attacks combining file encryption with pre-encryption data theft, backed by a Tor leak site with countdown timers and staged data releases.
  2. Initial access brokerage (IAB): Since November 2021, Everest has sold compromised network access and harvested credentials to other threat actors.
  3. Corporate insider recruitment: Since October 2023, the group has advertised cash payments and profit-sharing on dark web forums to employees willing to hand over remote access to organizations in the US, Canada, and Europe.

Everest generates its AES key locally on the compromised host rather than fetching it from a C2 server, so encryption does not depend on live C2 connectivity. This trait closely resembles the BlackByte ransomware family's C# variant.

How Does Everest Ransomware Work?

Everest follows a consistent execution flow [2]: gain initial access through exposed remote services or purchased/insider credentials, run network and credential discovery with off-the-shelf tools, disable defenses and recovery mechanisms, and encrypt files.

Below we explain each phase in more detail.

Initial Access

Everest gets into a network through internet-exposed RDP without MFA, or through vulnerable VPN endpoints that it finds already open.

It also gets in using valid accounts it did not have to breach itself: credentials purchased from other initial access brokers, credentials obtained through stuffing attacks, and access handed over directly by the group's own insider-recruitment program.

Anti-Analysis, Packing, and Anti-Tamper

A .NET sample of the ransomware is protected with ConfuserEx 1.x, with its watermark stripped.

The program's real entry point has been swapped out for a modified one. The numeric values in the code have been scrambled to make them harder to follow. The internal function and variable names have been shortened to meaningless labels. The class constructor section of the file (.cctor) is malformed in a way that is characteristic of this obfuscator rather than a normal compiler.

All literal strings, including the note text, mutex GUID, and command lines, are decrypted at runtime through a single routine:

<Module>.m(string) // GZip-decompress -> Base64-decode -> table lookup

Immediately after start-up, the process mutates its own security descriptor to block standard termination:

// Insert an AccessDenied ACE for the World SID (S-1-1-0) on the current process

RawSecurityDescriptor sd = GetKernelObjectSecurity(GetCurrentProcess(), DACL);

sd.DiscretionaryAcl.InsertAce(0,new CommonAce(AceFlags.None, AceQualifier.AccessDenied,accessMask: 0x1F0FFF, sid: WorldSid, ...));

SetKernelObjectSecurity(GetCurrentProcess(), DACL, sd);

This defeats ordinary user-mode termination (such as taskkill /F).

Discovery: Network and Host Enumeration

Reconnaissance combines a dedicated scanning tool with native Windows APIs. netscan.exe and netscanpack.exe (SoftPerfect Network Scanner) map the network and pull device information using multiple protocols. The output of this scan is consistently written to C:\Users\Public\Downloads\subnets.txt, with Active Directory trust enumeration output written to C:\Users\Public\Downloads\trustdumps.txt.

It also layers some additional LAN-enumeration sources on top of this:

net view # lists computers visible on the network

NetDfsEnum # enumerates Distributed File System (DFS) namespaces and shares

WNetEnumResource # enumerates network resources, including mapped/shared drives

WMI Win32_Share # lists shared folders/printers exposed by a host

WMI Win32_NetworkConnection # lists currently active network drive connections

WMI Win32_MappedLogicalDisk # lists locally mapped network drives

The host's ARP cache is also parsed directly, through ArpParser.ParseArpTable, which is backed by the arp -a command, to build a target list of IP and MAC address pairs.

Defense Evasion and Pre-Encryption Preparation

Before any file is touched, it runs a sequence of registry, service, and firewall changes:

# Disable Controlled Folder Access (Windows 10/11 ransomware-protection feature)

Set-MpPreference -EnableControlledFolderAccess Disabled


# Open File and Printer Sharing and Network Discovery on the host firewall

netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=Yes

netsh advfirewall firewall set rule group="Network Discovery" new enable=Yes


# Registry changes that widen SMB/NTLM behavior ahead of lateral movement

reg ADD ...\LongPathsEnabled = 1

reg ADD ...\LocalAccountTokenFilterPolicy = 1

reg ADD ...\EnableLinkedConnections = 1


# Grant world-writable ACLs across drives

icacls "C:*" /grant Everyone:F /T /C /Q

mountvol.exe # enumerate and mount unlettered \\?\Volume{...} volumes so they are also encrypted

Recovery mechanisms are also systematically destroyed before encryption:

vssadmin Delete Shadows /all /quiet

# PowerShell equivalent used in some runs:

Get-CimInstance Win32_ShadowCopy | Remove-CimInstance

Every System Restore point is removed via Srclient!SRRemoveRestorePoint, and backup files matching common patterns (*.VHD, *.bak, *.bkf, etc.) are deleted from every local drive letter with:

cmd.exe /c del /s /f /q <pattern>

It also specifically removes Raccine, an open-source anti-ransomware tool, by deleting its Image File Execution Options entries, HKLM\SOFTWARE\Raccine, its Run key entry, its scheduled task (Raccine Rules Updater), and by killing Raccine.exe / RaccineSettings.exe directly.

Encryption

Everest generates its AES key material locally rather than pulling it from a C2 server, the trait linking it to BlackByte. The RSA key pair is not generated locally: only the public half is baked into the binary in advance, and the matching private key stays with the attacker.

Everest builds a random seed, derives an AES key and IV from it, and encrypts that seed with the pre-embedded RSA public key so only the attacker can unwrap it.

To turn that seed into something usable, Everest works through three simple steps:

// Step 1: generate a 32-character random seed.

// Each character is a random printable ASCII character (values 33-126).

char c = (char) random.Next(33, 127);


// Step 2: turn the seed into the actual AES key and IV.

// Function: PBKDF2, a standard way to stretch a value into a usable key.

// Input: the 32-character seed from step 1.

// Output: a 16-byte AES key and a 16-byte IV, used to encrypt the files.


// Step 3: protect the seed so only the attacker can recover it.

The seed itself is generated fresh on the victim's machine (step 1 above).

RSA public key was baked into the binary in advance, before the attack, during the build process.

So here, that already-embedded key is simply used to encrypt the freshly generated seed.

Everest reuses one AES key and IV per run. Small files are fully encrypted; large files only partially. Encrypted files are renamed with the .everest extension.

How Picus Simulates Everest Ransomware Attacks?

We strongly suggest simulating Everest Ransomware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other ransomware variants, such as Warlock, BlackCat, Black Basta, and Akira, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the Everest Ransomware Attacks:

Threat ID

Threat Name

Attack Module

71267

Everest Ransomware Download Threat

Network Infiltration

81718

Everest Ransomware Email Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.

References

[1] “Everest.” Accessed: Jul. 10, 2026. [Online]. Available: https://www.halcyon.ai/threat-group/everest

[2] “Everest / Cti Report — Technical Analysis · RansomLook.” Accessed: Jul. 10, 2026. [Online]. Available: https://www.ransomlook.io/group/everest/analysis/cti_report

 
Everest is a Russian-speaking, closed-group ransomware operation active since December 2020 that encrypts Windows hosts using the .everest extension. Beyond deploying ransomware, Everest operates as an initial access broker and runs a paid corporate-insider recruitment program. The operation is written in C#/.NET and threatens victims with data leaks on a Tor-based leak site featuring countdown timers.
Everest enters networks through internet-exposed RDP without multi-factor authentication and vulnerable VPN endpoints it finds already open. It also uses valid accounts it did not breach itself, including credentials purchased from other initial access brokers, credentials gathered through stuffing attacks, and access supplied directly by the group's own insider-recruitment program.
Everest generates a 32-character random seed locally, then derives a 16-byte AES key and IV from it using PBKDF2. The seed is encrypted with a pre-embedded RSA public key, so only the attacker can recover it. One AES key and IV are reused per run. Small files are fully encrypted, large files partially, and encrypted files gain the .everest extension.
Everest generates its AES key material locally on the compromised host rather than fetching it from a command-and-control server, so encryption does not depend on live connectivity. This trait closely resembles the C# variant of the BlackByte ransomware family, forming the technical link between the two operations.
Before encryption, Everest disables Controlled Folder Access, opens File and Printer Sharing and Network Discovery, and grants world-writable ACLs across drives. It deletes shadow copies with vssadmin, removes every System Restore point, and deletes backup files matching patterns like .VHD, .bak, and .bkf. Everest also specifically removes the open-source anti-ransomware tool Raccine.
Picus recommends simulating Everest Ransomware attacks with the Picus Platform to validate security controls against real attacks. The Picus Threat Library includes the Everest Ransomware Download Threat and Everest Ransomware Email Threat. Teams can also test defenses against hundreds of other variants, including Warlock, BlackCat, Black Basta, and Akira, within minutes.

Table of Contents

Ready to start? Request a demo