Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier Breach — Threadlinqs Intelligence
As of 2026-07-23, Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier Breach is a medium-severity ransomware threat attributed to Everest, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1655 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Attribution: Everest · FINANCIAL
Swiss train manufacturer Stadler Rail refused a 10 million Swiss franc (~$12.3M) ransom demand from the Everest ransomware/extortion group after attackers used compromised credentials to steal
On or around mid-July 2026, the Russian-speaking extortion group Everest gained access to a file-sharing platform belonging to an unnamed third-party supplier of Swiss rail vehicle manufacturer Stadler Rail using compromised credentials. Rather than compromising Stadler's own network, the attackers exfiltrated technical documents that the supplier held on Stadler's behalf, then demanded 10 million Swiss francs (approximately $12.3 million USD) to prevent publication. Stadler publicly stated on July 22, 2026 that it would not pay, that no personal data was compromised, that its own IT systems and global train production/operations remained unaffected, and that it had filed a criminal complaint with Swiss authorities. As of the disclosure date, Everest had not yet listed Stadler on its dark-web leak site.
Everest is a closed-group, Russian-speaking ransomware and data-extortion operation active since December 2020 that has evolved a three-pronged business model: (1) traditional double-extortion ransomware deployment using a custom C#/.NET locker that appends the .everest extension, (2) initial-access brokerage (documented since November 2021, an unusual public-facing activity for a ransomware brand), and (3) paid corporate-insider recruitment (documented since October 2023) to obtain credentials or direct network access from employees or contractors. This incident is consistent with Everest's insider/access-broker model: the intrusion vector was a supply-chain trust relationship (a vendor's file-sharing platform) rather than direct exploitation of Stadler's perimeter, and no ransomware payload was reportedly deployed — the operation was pure data-theft extortion, a pattern Everest has increasingly favored to reduce forensic footprint and avoid destructive/encryption-based detection.
This is the second known extortion attempt against Stadler Rail: in May 2020, Stadler disclosed a malware-based network intrusion in which attackers claimed to have exfiltrated roughly 10,000 documents (~4 GB) and demanded approximately $6 million; Stadler refused, and the attackers subsequently published internal financial and administrative documents. The repeat targeting of the same manufacturer, five years apart, by different apparent extortion operators underscores continued interest in Stadler as a critical-infrastructure-adjacent (rail rolling stock) manufacturer, and highlights third-party/vendor risk as the now-preferred initial-access route given Stadler's own security posture holding in both incidents.
Everest's broader observed toolset — SoftPerfect Network Scanner for internal reconnaissance, Mimikatz and LSASS dumping for credential access, Cobalt Strike for lateral movement and C2, RDP and valid/purchased/insider-supplied accounts for lateral movement, and Rclone/WinSCP/WinRAR for staging and exfiltration — represents the standard playbook this actor would be expected to deploy if it escalates beyond the supplier's file-sharing platform into deeper network compromise. Everest also engages in pre-encryption defense evasion (shadow-copy and System Restore deletion, disabling Controlled Folder Access, removing the open-source anti-ransomware tool Raccine, deleting backup files) when it does deploy its locker, though no locker deployment has been reported in the Stadler case as of publication.
Weaknesses (CWE)
CWE-287, CWE-522, CWE-284
Target sectors: manufacturing, transport, rail, health, legal services, government administration, financial services, education, logistics, aviation, energy, cloud providers
Target regions: Europe, North America, Middle East, Asia
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, T1595, T1583, T1588, T1078, T1199, T1190, T1566, T1133, T1059, T1078