French and Ukranian law enforcement made the arrests after French authorities traced ransom payments to individuals located in Ukraine. Egregor is considered a variant of Ransom.Sekhmet based on similarities in encryption, obfuscation, API-calls, and its ransom note. The arrests come hot on the heels of the recent, dramatic takedown of Emotet and the surprise retirement of the Fonix ransomware group. The group is active worldwide and has achieved estimated earnings between $40 million and $50 million.”]
Source: https://blog.malwarebytes.com/ransomware/2021/02/egregor-ransomware-hit-by-arrests/