Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier Breach
Everest Ransomware Group Demands $12.3M from Stadler Rail (TL-2026-1655) is a medium-severity ransomware operation, first published 2026-07-22. It is attributed to Everest with medium confidence, affects Unnamed third-party supplier Third-party file-sharing platform, maps to 28 MITRE ATT&CK techniques (T1003, T1016, T1018), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-1655
- Threat ID
- TL-2026-1655
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-22
- Last reviewed
- 2026-07-22
- Attribution
- Everest
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, transport, rail, health, legal services, government administration, financial services, education, logistics, aviation, energy, cloud providers
- Target regions
- Europe, North America, Middle East, Asia
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Everest Ransomware Group Demands $12.3M from Stadler Rail
Malware and tooling: Everest, Cobalt Strike, ConfuserEx, Mimikatz, Rclone - S1040, SoftPerfect Network Scanner, UPX, WinSCP
Swiss train manufacturer Stadler Rail refused a 10 million Swiss franc (~$12.3M) ransom demand from the Everest ransomware/extortion group after attackers used compromised credentials to steal technical documents from a third-party supplier's file-sharing platform. Stadler's own systems and production were unaffected; the company filed a criminal complaint and did not negotiate.
How Everest Ransomware Group Demands $12.3M from Stadler Rail works
On or around mid-July 2026, the Russian-speaking extortion group Everest gained access to a file-sharing platform belonging to an unnamed third-party supplier of Swiss rail vehicle manufacturer Stadler Rail using compromised credentials. Rather than compromising Stadler's own network, the attackers exfiltrated technical documents that the supplier held on Stadler's behalf, then demanded 10 million Swiss francs (approximately $12.3 million USD) to prevent publication. Stadler publicly stated on July 22, 2026 that it would not pay, that no personal data was compromised, that its own IT systems and global train production/operations remained unaffected, and that it had filed a criminal complaint with Swiss authorities. As of the disclosure date, Everest had not yet listed Stadler on its dark-web leak site.
Everest is a closed-group, Russian-speaking ransomware and data-extortion operation active since December 2020 that has evolved a three-pronged business model: (1) traditional double-extortion ransomware deployment using a custom C#/.NET locker that appends the .everest extension, (2) initial-access brokerage (documented since November 2021, an unusual public-facing activity for a ransomware brand), and (3) paid corporate-insider recruitment (documented since October 2023) to obtain credentials or direct network access from employees or contractors. This incident is consistent with Everest's insider/access-broker model: the intrusion vector was a supply-chain trust relationship (a vendor's file-sharing platform) rather than direct exploitation of Stadler's perimeter, and no ransomware payload was reportedly deployed — the operation was pure data-theft extortion, a pattern Everest has increasingly favored to reduce forensic footprint and avoid destructive/encryption-based detection.
This is the second known extortion attempt against Stadler Rail: in May 2020, Stadler disclosed a malware-based network intrusion in which attackers claimed to have exfiltrated roughly 10,000 documents (~4 GB) and demanded approximately $6 million; Stadler refused, and the attackers subsequently published internal financial and administrative documents. The repeat targeting of the same manufacturer, five years apart, by different apparent extortion operators underscores continued interest in Stadler as a critical-infrastructure-adjacent (rail rolling stock) manufacturer, and highlights third-party/vendor risk as the now-preferred initial-access route given Stadler's own security posture holding in both incidents.
Everest's broader observed toolset — SoftPerfect Network Scanner for internal reconnaissance, Mimikatz and LSASS dumping for credential access, Cobalt Strike for lateral movement and C2, RDP and valid/purchased/insider-supplied accounts for lateral movement, and Rclone/WinSCP/WinRAR for staging and exfiltration — represents the standard playbook this actor would be expected to deploy if it escalates beyond the supplier's file-sharing platform into deeper network compromise. Everest also engages in pre-encryption defense evasion (shadow-copy and System Restore deletion, disabling Controlled Folder Access, removing the open-source anti-ransomware tool Raccine, deleting backup files) when it does deploy its locker, though no locker deployment has been reported in the Stadler case as of publication.
MITRE ATT&CK techniques used in TL-2026-1655
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Privilege Escalation
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing
Persistence
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Collection
T1213 Data from Information Repositories; T1560 Archive Collected Data
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
impact
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in Everest Ransomware Group Demands $12.3M from Stadler Rail
- Unnamed third-party supplier — Third-party file-sharing platform
Vulnerable versions: not disclosed
Fixed in: not disclosed - Stadler Rail AG — Corporate technical documentation (held by supplier, not Stadler-hosted)
Vulnerable versions: N/A - data exposure only, no software/version implicated
Fixed in: N/A
Remediation for Everest Ransomware Group Demands $12.3M from Stadler Rail
Immediate actions
- Audit and rotate all third-party/vendor credentials with access to file-sharing, ECM, or PLM platforms holding your organization's technical documentation
- Enforce MFA on all third-party/supplier-facing portals and file-sharing platforms, not only on internal accounts
- Review vendor access logs for anomalous authentication (new source IPs/geos, off-hours logins, bulk downloads) covering the incident window
- Notify and require incident confirmation from any supplier holding sensitive engineering/technical documentation
- Engage law enforcement and legal counsel; preserve logs for criminal complaint / forensic timeline reconstruction
Workarounds
- Restrict supplier file-sharing platform access to specific corporate IP ranges/VPN where feasible
- Require encrypted, access-logged document exchange (DRM/watermarking) for sensitive technical documentation shared with vendors
Longer-term hardening
- Implement a third-party risk management (TPRM) program with mandatory security requirements (MFA, logging, breach notification SLAs) for suppliers handling sensitive documents
- Deploy EDR with behavioral detection tuned for Mimikatz/LSASS access, SoftPerfect Network Scanner artifacts, Rclone/WinSCP exfiltration, and Cobalt Strike beacon patterns
- Segment and minimize the scope of technical/engineering data shared with external suppliers to least-privilege
- Establish continuous monitoring for organization name/brand mentions on ransomware leak sites
- Run tabletop exercises simulating third-party/supply-chain data-extortion scenarios
Weaknesses (CWE) in Everest Ransomware Group Demands $12.3M from Stadler Rail
CWE-287, CWE-522, CWE-284
Timeline of Everest Ransomware Group Demands $12.3M from Stadler Rail
- Stadler Rail discloses a malware-based intrusion into its own IT network; attackers claim theft of roughly 10,000 documents (~4 GB) and demand approximately $6 million USD in Bitcoin.
- After Stadler refuses to pay the 2020 ransom, attackers publish internal financial and administrative documents online to pressure the company.
- Everest's initial-access-broker activity is first publicly documented, marking an unusual dual business model (ransomware operator + access broker) for the group.
- Everest begins a paid corporate-insider recruitment program, offering payment to employees/contractors for credentials or direct network access.
- Everest claims responsibility for a breach of Swedish electricity grid operator Svenska kraftnat.
- Everest claims responsibility for a breach of a Nissan contractor.
- Everest uses compromised credentials to access a third-party supplier's file-sharing platform and exfiltrates Stadler Rail technical documents held by that supplier.
- Stadler Rail publicly confirms the incident, states it refuses the 10 million CHF (~$12.3M) ransom demand, confirms no personal data or production impact, and reports filing a criminal complaint; Everest has not yet listed Stadler on its leak site.
Sources cited for Everest Ransomware Group Demands $12.3M from Stadler Rail
- Stadler refuses Everest ransom demand
- Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
- Stadler Rail refuses to pay $12.3 million ransom after ransomware attack
- Ransomware Spotlight: Everest's Focus on Initial Access
- Everest Ransomware: Triple Threat of Encryption, Access, and Insiders
- Everest Ransomware Group – Threat Actor Profile
- Railway Vehicle Maker Stadler Hit by Malware Attack
- Internal documents published after Stadler refuses $US 6m ransom
- Swiss rail vehicle manufacturer Stadler hit by a malware-based attack
Threats related to Everest Ransomware Group Demands $12.3M from Stadler Rail
- Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused
- Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider Recruitment
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom
- Fake Interpol Investigation Emails Deliver Custom Ransomware to Small Businesses
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims
Detection coverage for TL-2026-1655
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1655 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.