LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0554: Egregor

MITRE ATT&CK S0554: Egregor Malware details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS0554MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Egregor is a Windows ransomware-as-a-service tool documented by ATT&CK, with reported code similarities to Sekhmet and Maze. Its relationship set matters because it spans more than encryption: discovery of users, groups, systems, network connections, use of PowerShell/cmd and Windows utilities, remote access tooling, stealth techniques, network share collection, Group Policy modification, and data encryption for impact. For leaders, this is a reminder that ransomware readiness is not just backup quality; it depends on whether identity, endpoint, network, and Windows administration telemetry can show the path to impact before or during an incident.

Executive priority

Treat this object as a ransomware resilience validation case. Ask whether the organization can prove coverage for Windows execution, domain and user discovery, remote access tool use, Group Policy changes, suspicious BITS jobs, regsvr32/rundll32 abuse, process injection indicators, network share access, and early signs of mass encryption. Prioritize controls and evidence that reduce blast radius: privileged access governance, change control over GPOs, monitored administrative tooling, segmentation around shared drives, and tested recovery processes. Because ATT&CK provides no official detection text for Egregor, local validation and incident response playbooks should drive confidence rather than assumptions of tool-specific detection.

Technical view

SOC and IR teams should map Egregor-related coverage to the listed ATT&CK relationships: execution through PowerShell, Windows Command Shell, Native API, DLL abuse, Regsvr32, Rundll32, and BITS Jobs; discovery through system owner/user, domain groups, system information, network connections, and system time; stealth through packing, deobfuscation, masqueraded tasks/services, process injection, and sandbox/time checks; command-and-control or staging through web protocols, ingress tool transfer, and remote access tools; collection from network shared drives; privilege or defense impairment through Group Policy modification; and impact through data encryption. Since the base malware object lists Windows as the platform and no official detection is supplied, detections should be behavior-led and tested against benign administrative baselines.

Likely telemetry

  • Windows endpoint process creation and command-line logging for PowerShell, cmd.exe, regsvr32.exe, rundll32.exe, and BITS-related activity
  • PowerShell script block, module, and transcription logs where enabled
  • Windows service, scheduled task, and task/service naming telemetry for masquerading review
  • EDR telemetry for process injection, suspicious DLL loading, packed executables, and in-memory execution patterns
  • Active Directory and domain controller logs for domain group enumeration and Group Policy Object modification

Detection direction

  • Build behavior-based detections across the related techniques rather than relying on an Egregor-specific signature, because official ATT&CK detection guidance is not provided.
  • Tune PowerShell, cmd.exe, regsvr32.exe, rundll32.exe, BITS, and DLL-loading detections against known administrative and software-management activity to reduce false positives.
  • Correlate discovery behaviors with later tool transfer, remote access, network share access, GPO modification, or encryption activity; individual discovery commands may be benign, but clustering increases investigative value.
  • Monitor GPO modifications as high-value events, especially changes affecting security controls, scripts, startup behavior, or domain-wide configuration.
  • Validate visibility on network shared drives, since ransomware impact and data collection can occur through accessible shares rather than only local disks.

Mitigation priorities

  • Prioritize resilient recovery: tested backups, restoration procedures, and protection of backup infrastructure from domain-wide compromise.
  • Harden identity and Windows administration paths: restrict privileged groups, monitor domain group changes, and enforce change control for Group Policy.
  • Limit lateral reach to shared drives using least privilege, segmentation, and auditing of sensitive file repositories.
  • Constrain and monitor scripting and living-off-the-land utilities such as PowerShell, cmd.exe, BITS, regsvr32.exe, and rundll32.exe according to business need.
  • Govern legitimate remote access tools with approved inventories, authentication controls, logging, and exception review.
Additional notes and limits

The object is a malware entry for Egregor, external ID S0554, in the enterprise ATT&CK domain, with Windows as the listed platform. ATT&CK describes it as Ransomware-as-a-Service first observed in September 2020 and cites NHS Digital, Cyble, and Security Boulevard reporting, including noted code similarities with Sekhmet and Maze. The most useful defensive value comes from the relationship context: Egregor is linked to execution, stealth, discovery, collection, command-and-control, privilege/defense impairment, and impact techniques.

ATT&CK provides no official detection text, no aliases, and no object-level tactics for this entry. The relationship techniques provide behavior context, but they do not prove activity in any specific environment or guarantee that a given control detects Egregor. Local telemetry availability, Windows logging configuration, EDR visibility, identity architecture, remote access tool inventory, and file share design are required to assess actual exposure and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Egregor

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

25 rows
DomainIDNameRelationship / procedure
EnterpriseT1497.003Time Based ChecksSub-techniqueThis object uses Time Based Checks.
EnterpriseT1218.011Rundll32Sub-techniqueThis object uses Rundll32.
EnterpriseT1197BITS JobsThis object uses BITS Jobs.
EnterpriseT1124System Time DiscoveryThis object uses System Time Discovery.
EnterpriseT1027.002Software PackingSub-techniqueThis object uses Software Packing.
EnterpriseT1039Data from Network Shared DriveThis object uses Data from Network Shared Drive.
EnterpriseT1106Native APIThis object uses Native API.
EnterpriseT1140Deobfuscate/Decode Files or InformationThis object uses Deobfuscate/Decode Files or Information.
EnterpriseT1036.004Masquerade Task or ServiceSub-techniqueThis object uses Masquerade Task or Service.
EnterpriseT1049System Network Connections DiscoveryThis object uses System Network Connections Discovery.
EnterpriseT1033System Owner/User DiscoveryThis object uses System Owner/User Discovery.
EnterpriseT1105Ingress Tool TransferThis object uses Ingress Tool Transfer.
EnterpriseT1685Disable or Modify ToolsThis object uses Disable or Modify Tools.
EnterpriseT1497Virtualization/Sandbox EvasionThis object uses Virtualization/Sandbox Evasion.
EnterpriseT1574.001DLLSub-techniqueThis object uses DLL.
EnterpriseT1486Data Encrypted for ImpactThis object uses Data Encrypted for Impact.
EnterpriseT1069.002Domain GroupsSub-techniqueThis object uses Domain Groups.
EnterpriseT1218.010Regsvr32Sub-techniqueThis object uses Regsvr32.
EnterpriseT1071.001Web ProtocolsSub-techniqueThis object uses Web Protocols.
EnterpriseT1219Remote Access ToolsThis object uses Remote Access Tools.
EnterpriseT1059.003Windows Command ShellSub-techniqueThis object uses Windows Command Shell.
EnterpriseT1484.001Group Policy ModificationSub-techniqueThis object uses Group Policy Modification.
EnterpriseT1055Process InjectionThis object uses Process Injection.
EnterpriseT1059.001PowerShellSub-techniqueThis object uses PowerShell.
EnterpriseT1082System Information DiscoveryThis object uses System Information Discovery.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
17d0e143e52e9a45...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle17d0e143e52e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  2. [2]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  3. [3]
    Security Boulevard Egregor Oct 2020

    Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.

    Open source URL
  4. [4]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  5. [5]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  6. [6]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  7. [7]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  8. [8]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  9. [9]
    Egregor

    (Citation: NHS Digital Egregor Nov 2020)(Citation: Cyble Egregor Oct 2020)

  10. [10]
    Egregor

    (Citation: NHS Digital Egregor Nov 2020)(Citation: Cyble Egregor Oct 2020)

  11. [11]
    Egregor

    (Citation: NHS Digital Egregor Nov 2020)(Citation: Cyble Egregor Oct 2020)

  12. [12]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  13. [13]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  14. [14]
    Security Boulevard Egregor Oct 2020

    Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.

    Open source URL
  15. [15]
    Security Boulevard Egregor Oct 2020

    Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.

    Open source URL
  16. [16]
    mitre-attackS0554
    Open source URL
  17. [17]
    mitre-attackS0554
    Open source URL
  18. [18]
    mitre-attackS0554
    Open source URL
  19. [19]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  20. [20]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  21. [21]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  22. [22]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  23. [23]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  24. [24]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  25. [25]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  26. [26]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  27. [27]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  28. [28]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  29. [29]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  30. [30]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  31. [31]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  32. [32]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  33. [33]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  34. [34]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  35. [35]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  36. [36]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  37. [37]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  38. [38]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  39. [39]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  40. [40]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  41. [41]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  42. [42]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  43. [43]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  44. [44]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  45. [45]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  46. [46]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  47. [47]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  48. [48]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  49. [49]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  50. [50]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  51. [51]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  52. [52]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  53. [53]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  54. [54]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  55. [55]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  56. [56]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  57. [57]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  58. [58]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  59. [59]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  60. [60]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  61. [61]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  62. [62]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  63. [63]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  64. [64]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  65. [65]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  66. [66]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  67. [67]
    Cybereason Egregor Nov 2020

    Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

    Open source URL
  68. [68]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  69. [69]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  70. [70]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  71. [71]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  72. [72]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.