EV

everest

Known ransomware group ACTIVE
Active · high-tempo

Everest is a Russian-speaking extortion group active since 2020 that combines ransomware with initial-access brokering, sometimes selling network access rather than deploying encryptors. It has targeted government, healthcare, and industrial victims.

17

Total Claims

9

Critical

Records Claimed

8

Industries Hit

Active span: Apr 13, 2026 – May 28, 2026 · 17 organizations targeted

Active · high-tempo
Activity 7.8 Severity 8.8 Sectors 7.3 Tooling 5.0

Actor Threat Profile

Activity Timeline

Peak: May 2026 (10)
Apr 2026
LessMore
May 2026

Share this profile

Shareable intel card for everest

Top Targeted Industries

Healthcare 4
Financial Services 4
Business Services 4
Technology 1
Manufacturing 1
Agriculture and Food Production 1

Tradecraft & Infrastructure

8

Documented tools

5 / 17

MITRE tactics / techniques

1

Known leak sites

CredentialTheftDiscoveryEnumOffsecRMM-Tools
Full intelligence profile on ransomware.live →

Claims by everest

Critical

Ransomware Claim: L&P Aesthetics

L&P Aesthetics
everest
Ransomware Healthcare
Jun 2, 2026
Critical

Ransomware Claim: Advanced Psychiatry Associates

Advanced Psychiatry Associates
everest
Ransomware Healthcare
May 29, 2026
Critical

Ransomware Claim: Sidra Kuwait Hospital

Sidra Kuwait Hospital
everest
Ransomware Healthcare
May 29, 2026
Critical

Ransomware Claim: VVO Finance

VVO Finance
everest
Ransomware Financial Services
May 29, 2026
Critical

Ransomware Claim: Rehab Clinics Group Ltd

Rehab Clinics Group Ltd
everest
Ransomware Healthcare
May 8, 2026
High

Ransomware Claim: Studio Marchi - Studio Professionale Associato

Studio Marchi - Studio Professionale Associato
everest
Ransomware Business Services
May 5, 2026
Critical

Ransomware Claim: Fiserv

Fiserv
everest
Ransomware Financial Services
May 3, 2026
Critical

Ransomware Claim: TSYS

TSYS
everest
Ransomware Financial Services
May 2, 2026
High

Ransomware Claim: Epiq Global

Epiq Global
everest
Ransomware Business Services
May 2, 2026
High

Ransomware Claim: Symcor

Symcor
everest
Ransomware Business Services
May 2, 2026
High

Ransomware Claim: Super AI

Super AI
everest
Ransomware Technology
Apr 28, 2026
Critical

Ransomware Claim: Citizens Bank

Citizens Bank
everest
Ransomware Financial Services
Apr 20, 2026
High

Ransomware Claim: Complete Aircraft Group

Complete Aircraft Group
everest
Ransomware Manufacturing
Apr 20, 2026
High

Ransomware Claim: Nutrabio

Nutrabio
everest
Ransomware Agriculture and Food Production
Apr 20, 2026
High

Ransomware Claim: Tokoparts

Tokoparts
everest
Ransomware Consumer Services
Apr 20, 2026
High

Ransomware Claim: Umiles Group

Umiles Group
everest
Ransomware Business Services
Apr 20, 2026
Critical

Ransomware Claim: K Subsea Group

K Subsea Group
everest
Ransomware Energy
Apr 13, 2026

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.