-

Dark Web Intelligence Shows Everest Ransomware Group Increasing Initial Access Broker Activity

Searchlight Cyber publishes report on the dark web activity of the Everest ransomware group

WASHINGTON & PORTSMOUTH, England--(BUSINESS WIRE)--Searchlight Cyber, the dark web intelligence company, has published new research on the Everest Ransomware group. The findings were shared in a written report, available to Ransomware Spotlight subscribers, and a webinar hosted by the Searchlight Cyber threat intelligence team.

The Everest ransomware group has been around since at least December 2020, targeting organizations across a number of industries and regions but with a particular concentration in the Americas and capital goods, health, and the public sector. It has listed 92 organizations on its dark web leak site, and is perhaps most infamous for targeting AT&T and several South American governments.

Searchlight Cyber’s Ransomware Spotlight report focuses on the Everest groups’ increasing output as an “Initial Access Broker” – a cybersecurity term for criminals who sell backdoors into organizations to other criminals but don’t carry out the attack themselves. This behavior is extremely rare among ransomware groups, as a ransomware attack would typically make more money than selling initial access.

The Everest ransomware group often deletes its advertisements from its leak site, which means that other security professionals might not be aware of how frequently the group is acting as an Initial Access Broker.

The report explores several reasons why Everest group may have moved towards being an Initial Access Broker, including trying to keep a low profile from law enforcement, a loss of personnel, or as a different monetization tactic. It also gives an overview of the Everest group’s dark web presence - including its use of dark web hacking forums such as XSS to promote its attacks, the group’s victimology based on the companies it posts on its dark web blog, and known TTPs for the group.

Click here to subscribe to Ransomware Spotlight and receive a copy of the Everest ransomware group report.

Click here to listen to the on demand webinar “Ransomware spotlight on Everest group: Unveiling the latest dark web ransomware trends”.

ENDS

About Searchlight Cyber

Searchlight Cyber provides organizations with relevant and actionable dark web intelligence, to help them identify and prevent criminal activity. Founded in 2017 with a mission to stop criminals acting with impunity on the dark web, we have been involved in some of the world’s largest dark web investigations and have the most comprehensive dataset based on proprietary techniques and ground-breaking academic research. Today we help government and law enforcement, enterprises, and managed security services providers around the world to illuminate deep and dark web threats and prevent attacks. To find out more visit slcyber.io or follow Searchlight Cyber on LinkedIn and Twitter.

More News From Searchlight

Searchlight Cyber Releases AI Agent-Generated Threat Actor Summaries

PORTSMOUTH, England--(BUSINESS WIRE)--Searchlight Cyber has released a new AI capability that summarizes the activity of a threat actor in its dark web investigation platform, Cerberus. The Searchlight AI Agent uses the Cerberus’ dark web data lake to provide a quick overview of a threat actor - including their activity, conversation history, aliases, and associations - helping law enforcement and cybersecurity professionals to quickly identify profiles of interest and areas of investigation to...

Searchlight Cyber Partners With TRM Labs to Bring Enhanced Cryptocurrency Analysis to Its Dark Web Investigation Platform

PORTSMOUTH, England & SAN FRANCISCO--(BUSINESS WIRE)--Searchlight Cyber has partnered with TRM Labs, the leading provider of blockchain intelligence solutions, to integrate new cryptocurrency analysis capabilities into its dark web investigation platform. The blockchain data provided by TRM Labs allows investigators to identify wallets linked to illicit activity, helping to combat crime ranging from ransomware attacks, to drug trafficking, to financial misconduct. The blockchain intelligence pr...

Searchlight Cyber Supports the U.S. Government Takedown of the BidenCash Dark Web Marketplace

ALEXANDRIA, Va.--(BUSINESS WIRE)--Searchlight Cyber provided technical capabilities to support the law enforcement takedown of the dark web marketplace BidenCash, announced this week by the U.S. Department of Justice. The operation involved the seizure of 145 dark web and traditional internet domains, and cryptocurrency funds associated with the marketplace. The BidenCash marketplace domains are no longer operational and will redirect to a U.S. law enforcement-controlled server, preventing futu...
Back to Newsroom