S0554: Egregor
MITRE ATT&CK S0554: Egregor Malware details for Windows, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
Egregor is a Windows ransomware-as-a-service tool documented by ATT&CK, with reported code similarities to Sekhmet and Maze. Its relationship set matters because it spans more than encryption: discovery of users, groups, systems, network connections, use of PowerShell/cmd and Windows utilities, remote access tooling, stealth techniques, network share collection, Group Policy modification, and data encryption for impact. For leaders, this is a reminder that ransomware readiness is not just backup quality; it depends on whether identity, endpoint, network, and Windows administration telemetry can show the path to impact before or during an incident.
Executive priority
Treat this object as a ransomware resilience validation case. Ask whether the organization can prove coverage for Windows execution, domain and user discovery, remote access tool use, Group Policy changes, suspicious BITS jobs, regsvr32/rundll32 abuse, process injection indicators, network share access, and early signs of mass encryption. Prioritize controls and evidence that reduce blast radius: privileged access governance, change control over GPOs, monitored administrative tooling, segmentation around shared drives, and tested recovery processes. Because ATT&CK provides no official detection text for Egregor, local validation and incident response playbooks should drive confidence rather than assumptions of tool-specific detection.
Technical view
SOC and IR teams should map Egregor-related coverage to the listed ATT&CK relationships: execution through PowerShell, Windows Command Shell, Native API, DLL abuse, Regsvr32, Rundll32, and BITS Jobs; discovery through system owner/user, domain groups, system information, network connections, and system time; stealth through packing, deobfuscation, masqueraded tasks/services, process injection, and sandbox/time checks; command-and-control or staging through web protocols, ingress tool transfer, and remote access tools; collection from network shared drives; privilege or defense impairment through Group Policy modification; and impact through data encryption. Since the base malware object lists Windows as the platform and no official detection is supplied, detections should be behavior-led and tested against benign administrative baselines.
Likely telemetry
- Windows endpoint process creation and command-line logging for PowerShell, cmd.exe, regsvr32.exe, rundll32.exe, and BITS-related activity
- PowerShell script block, module, and transcription logs where enabled
- Windows service, scheduled task, and task/service naming telemetry for masquerading review
- EDR telemetry for process injection, suspicious DLL loading, packed executables, and in-memory execution patterns
- Active Directory and domain controller logs for domain group enumeration and Group Policy Object modification
Detection direction
- Build behavior-based detections across the related techniques rather than relying on an Egregor-specific signature, because official ATT&CK detection guidance is not provided.
- Tune PowerShell, cmd.exe, regsvr32.exe, rundll32.exe, BITS, and DLL-loading detections against known administrative and software-management activity to reduce false positives.
- Correlate discovery behaviors with later tool transfer, remote access, network share access, GPO modification, or encryption activity; individual discovery commands may be benign, but clustering increases investigative value.
- Monitor GPO modifications as high-value events, especially changes affecting security controls, scripts, startup behavior, or domain-wide configuration.
- Validate visibility on network shared drives, since ransomware impact and data collection can occur through accessible shares rather than only local disks.
Mitigation priorities
- Prioritize resilient recovery: tested backups, restoration procedures, and protection of backup infrastructure from domain-wide compromise.
- Harden identity and Windows administration paths: restrict privileged groups, monitor domain group changes, and enforce change control for Group Policy.
- Limit lateral reach to shared drives using least privilege, segmentation, and auditing of sensitive file repositories.
- Constrain and monitor scripting and living-off-the-land utilities such as PowerShell, cmd.exe, BITS, regsvr32.exe, and rundll32.exe according to business need.
- Govern legitimate remote access tools with approved inventories, authentication controls, logging, and exception review.
Additional notes and limits
The object is a malware entry for Egregor, external ID S0554, in the enterprise ATT&CK domain, with Windows as the listed platform. ATT&CK describes it as Ransomware-as-a-Service first observed in September 2020 and cites NHS Digital, Cyble, and Security Boulevard reporting, including noted code similarities with Sekhmet and Maze. The most useful defensive value comes from the relationship context: Egregor is linked to execution, stealth, discovery, collection, command-and-control, privilege/defense impairment, and impact techniques.
ATT&CK provides no official detection text, no aliases, and no object-level tactics for this entry. The relationship techniques provide behavior context, but they do not prove activity in any specific environment or guarantee that a given control detects Egregor. Local telemetry availability, Windows logging configuration, EDR visibility, identity architecture, remote access tool inventory, and file share design are required to assess actual exposure and coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Egregor
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1497.003 | Time Based ChecksSub-technique | This object uses Time Based Checks. |
| Enterprise | T1218.011 | Rundll32Sub-technique | This object uses Rundll32. |
| Enterprise | T1197 | BITS Jobs | This object uses BITS Jobs. |
| Enterprise | T1124 | System Time Discovery | This object uses System Time Discovery. |
| Enterprise | T1027.002 | Software PackingSub-technique | This object uses Software Packing. |
| Enterprise | T1039 | Data from Network Shared Drive | This object uses Data from Network Shared Drive. |
| Enterprise | T1106 | Native API | This object uses Native API. |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | This object uses Deobfuscate/Decode Files or Information. |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | This object uses Masquerade Task or Service. |
| Enterprise | T1049 | System Network Connections Discovery | This object uses System Network Connections Discovery. |
| Enterprise | T1033 | System Owner/User Discovery | This object uses System Owner/User Discovery. |
| Enterprise | T1105 | Ingress Tool Transfer | This object uses Ingress Tool Transfer. |
| Enterprise | T1685 | Disable or Modify Tools | This object uses Disable or Modify Tools. |
| Enterprise | T1497 | Virtualization/Sandbox Evasion | This object uses Virtualization/Sandbox Evasion. |
| Enterprise | T1574.001 | DLLSub-technique | This object uses DLL. |
| Enterprise | T1486 | Data Encrypted for Impact | This object uses Data Encrypted for Impact. |
| Enterprise | T1069.002 | Domain GroupsSub-technique | This object uses Domain Groups. |
| Enterprise | T1218.010 | Regsvr32Sub-technique | This object uses Regsvr32. |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | This object uses Web Protocols. |
| Enterprise | T1219 | Remote Access Tools | This object uses Remote Access Tools. |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | This object uses Windows Command Shell. |
| Enterprise | T1484.001 | Group Policy ModificationSub-technique | This object uses Group Policy Modification. |
| Enterprise | T1055 | Process Injection | This object uses Process Injection. |
| Enterprise | T1059.001 | PowerShellSub-technique | This object uses PowerShell. |
| Enterprise | T1082 | System Information Discovery | This object uses System Information Discovery. |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.0 | Current bundle | 17d0e143e52e… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [2]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [3]Security Boulevard Egregor Oct 2020
Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.
Open source URL - [4]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [5]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [6]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [7]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [8]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [9]Egregor
(Citation: NHS Digital Egregor Nov 2020)(Citation: Cyble Egregor Oct 2020)
- [10]Egregor
(Citation: NHS Digital Egregor Nov 2020)(Citation: Cyble Egregor Oct 2020)
- [11]Egregor
(Citation: NHS Digital Egregor Nov 2020)(Citation: Cyble Egregor Oct 2020)
- [12]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [13]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [14]Security Boulevard Egregor Oct 2020
Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.
Open source URL - [15]Security Boulevard Egregor Oct 2020
Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.
Open source URL - [16]mitre-attackS0554Open source URL
- [17]mitre-attackS0554Open source URL
- [18]mitre-attackS0554Open source URL
- [19]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [20]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [21]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [22]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [23]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [24]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [25]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [26]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [27]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [28]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [29]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [30]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [31]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [32]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [33]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [34]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [35]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [36]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [37]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [38]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [39]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [40]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [41]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [42]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [43]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [44]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [45]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [46]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [47]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [48]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [49]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [50]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [51]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [52]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [53]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [54]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [55]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [56]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [57]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL - [58]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [59]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [60]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [61]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [62]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [63]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [64]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [65]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [66]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [67]Cybereason Egregor Nov 2020
Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Open source URL - [68]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [69]Cyble Egregor Oct 2020
Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Open source URL - [70]Intrinsec Egregor Nov 2020
Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Open source URL - [71]JoeSecurity Egregor 2020
Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
Open source URL - [72]NHS Digital Egregor Nov 2020
NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
