Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 22:25:42 UTC Home > List all groups > List all tools > List all groups using tool Egregor Tool: Egregor Names Egregor Category Malware Type Ransomware, Big Game Hunting Description (Malwarebytes) Egregor ransomware is a relatively new ransomware (first spotted in September 2020) that seems intent on making its way to the top right now. Egregor is considered a variant of Ransom.Sekhmet based on similarities in obfuscation, API-calls, and the ransom note. As we’ve reported in the past, affiliates that were using Maze ransomware started moving over to Egregor even before the Maze gang officially announced they were calling it quits. Information MITRE ATT&CK Malpedia AlienVault OTX https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833 Page 1 of 2 Playbook Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool Egregor Changed Name Country Observed APT groups Mallard Spider [Unknown] 2008-Dec 2020 TA2101, Maze Team [Unknown] 2019-Feb 2024 2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833 Page 2 of 2