Security researchers from Appgate are warning about a newly discovered ransomware called Egregor. The ransomware has infected around a dozen organizations around the world in recent months.

The operators of the Egregor ransomware are following a new trend in ransomware attacks , threatening to leak data their victims' ransom within three days. This trend was started by the Maze hackers and has been followed by many other groups.
The criminals behind the Egregor ransomware have created a “news” site on the darknet and are offering a list of victims, as well as updates on when the stolen data will be leaked.
The ransom note states that if the victim pays, the hackers will provide the decryption key and offer some security to protect the company from future attacks. According to the researchers, in this way, the attackers are operating as a “black hat pentest team.”
At the moment, we don’t know how much money the Egregor ransomware hackers are demanding or whether any victims’ data has already been leaked. A copy of a note shows that the criminals intend to leak the stolen data via “media.”.
The Egregor ransomware was first detected in mid-September by several security, including Michael Gillespie, who posted a sample of the hackers' note on Twitter.
Appgate researchers analyzed the ransomware last week and don't know many details about when the attacks started. However, Egregor's first appearance on Twitter was on September 18, by @demonslay335 and @PolarToffee.

Avoiding detection
According to Appgate, Egregor ransomware appears to be derived from another ransomware called Sekhmet , which also exposes victims' data
While analyzing Egregor, researchers discovered that the ransomware uses techniques to avoid detection (code obfuscation, packed payloads) by security.
Appgate analysts also noted that without the correct decryption key, it is difficult to analyze the full ransomware payloadto reveal details about how it operates.
Egregor ransomware: Threats to leak stolen data
As we said above, no leak related to Egregor has been reported yet , but like most ransomware gangs , it uses this technique to pressure victims.
