Quick Summary
AllegedExecutive Summary
NIMR Oil, an energy and utilities company based in the United Arab Emirates, has been listed as a victim on the Everest ransomware group’s dark web portal, published on August 5, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company operates in the oil and energy sector, a vertical where operational technology dependencies raise the stakes of any IT compromise. It is one of three UAE entries in Everest’s recent listing population. In the 60 days prior to this listing, Everest has claimed 18 other victims across its leak portal. The group has shown a strong targeting pattern in the technology, professional services, and energy and utilities sectors. Geographically, its victims are concentrated in the United States, India, and the United Arab Emirates. Other recent Everest listings that overlap with NIMR Oil’s profile — energy organisations or UAE-based companies — include EPM, Al-Futtaim Group, Emirates Flight Catering, and Keysight. NIMR Oil aligns with the group’s recent pattern on both axes, sitting inside both the Emirati cluster and the smaller energy cohort.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the nimroil.com domain. The returned sample was small — five records — but all bore corporate usernames, and one authenticated directly against the organisation’s cloud identity provider while the remainder appeared on external third-party services. Log activity extends into June 2026. A five-record sample is thin evidence in isolation; what elevates it is that every record is corporate and one touches federation infrastructure. The profile is mixed, weighted toward workstation compromise with a single high-value identity exposure. For ransomware groups such as Everest, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Everest, a single validated identity-provider credential is often all a broker needs to package and sell access. CTI teams tracking this listing should treat the exposed corporate identities as a standing risk and prioritise credential rotation and session invalidation over point-in-time assessment.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.