On February 12, French radio station “France Inter” announced that members of the Egregor ransomware cartel had been arrested in Ukraine. The arrests, which have not yet been officially announced, came after a joint investigation by French and Ukrainian police. The names of the suspects have not been released. According to France Inter, the arrested individuals provided hacking, logistical and financial support to the Egregor ransomware gang.
The Egregor gang, which began operating in September 2020, operates on a Ransomware-as-a-Service (RaaS) model. Hackers rent access to the actual ransomware strain, but rely on other hacking gangs to orchestrate intrusions into corporate networks and deploy the ransomware, with the goal of encrypting files.

Victims who refuse to give in to the gang's blackmail are often referred to a leak site, where the hackers attempt to "sham" them into paying the demanded ransom. Additionally, the Egregor ransomware hackers often share internal documents and files to punish victims who don't pay.
If victims pay the ransom, the gang that orchestrated the attack keeps most of the money, while Egregor's gang takes a small cut of the proceeds. The gang then distributes these profits through the Bitcoin, via Bitcoin mixing services.

As France Inter reports, French authorities joined the investigation because several large French companies were affected by Egregor in 2020, such as gaming company “Ubisoft” and logistics company “Gefco.” Thus, French police, together with “European counterparts,” were able to identify Egregor’s members and infrastructure in Ukraine.
According to ZDNet, the arrests in Ukraine appear to have had a major impact on the operations of the Egregor ransomware. Specifically, Allan Liska, a security researcher at threat intelligence firmRecorded Future, told ZDNet that the firm has observed that Egregor's infrastructure, including the ransomware site and command and control (C2) infrastructure, have been offline since at least February 12.
Egregor has emerged as one of the most dangerous ransomware gangs of 2020, hitting a large number of companies around the world. While Egregor RaaS was officially launched in September 2020, many security experts believe that the Egregor gang is actually an upgraded and renamed version of the Maze ransomware cartel, which began operating in late 2019. The Maze gang abruptly ceased operations in September 2020, just weeks after Egregor went live.

It is unclear how much damage the arrests will do to Egregor's future. Last month, US and Bulgarian authorities disrupted the Netwalker ransomware gang, seizing its servers and arresting one of its associates, and the RaaS service has been inactive since then.
A report from Chainalysis published early this month reported the Egregor / Maze gang as one of the 5 most profitable ransomware gangs, with earnings between 40 million and 50 million dollars.
