Everest
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Everest ransomware group is an alias used by a threat actor. The alias has been linked to a single publicly reported incident. The group came to attention in early April 2026. The incident involved a breach affecting Adobe. No other aliases or alternative names are provided in the source material.
According to the reported incident, the attack began with a phishing email. The phishing email delivered a remote access tool. The tool was received by an employee of an Indian business process outsourcing contractor that supports Adobe. The remote access tool allowed the attackers to obtain an initial foothold in the contractor’s network. From that foothold the attackers pivoted to a manager’s account within the contractor’s environment. Using the compromised manager’s account the threat actors moved laterally to Adobe’s helpdesk system. Once inside the helpdesk system they were able to export all support tickets. The exported data reportedly included 13 million customer support tickets. The exported data also included 15 000 employee records. The exported data further included the complete set of HackerOne bug bounty submissions. The submissions contained customer names, email addresses, account IDs, internal technical notes, and unpublished vulnerability reports. Adobe has not publicly confirmed or denied the breach.
No additional campaigns or operations involving Everest ransomware group are described in the available information. Therefore further details about its typical targets, geographic focus, or strategic objectives cannot be derived. Likewise, the source material does not provide any evidence linking the group to a state sponsor. The source material also does not provide evidence linking the group to a criminal consortium. The source material does not provide evidence linking the group to any other affiliate structure. Consequently, the public record of Everest ransomware group remains limited to the single Adobe‑related incident described above.
Incidents
Attributed incidents are available to members.
1 incident