Last seven days
- First activity
- Sep 3, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
M0yv is a modular x86/x64 Windows file-infector malware associated with the Maze ransomware ecosystem.
Profile source: Mallory opens in a new tabM0yv
M0yv is a modular x86/x64 Windows file-infector malware associated with the Maze ransomware ecosystem. It targets Portable Executable files on Windows and has been described as a file-infecting virus that can extend beyond simple parasitic infection to function as a dropper and remote access trojan. Publicly discussed source code attributed to the Maze operation indicates that M0yv formed part of that group’s broader tooling arsenal.
A notable feature of M0yv is its domain generation algorithm, which produces pseudo-random command-and-control domains from embedded seeds. Research on the malware’s DGA and subsequent sinkholing activity indicates that M0yv used algorithmically generated domains to support resilient network communications and hinder straightforward infrastructure blocking. This behavior aligns with its use as a backdoor-capable platform rather than a purely destructive or self-contained file infector.
M0yv is primarily a Windows threat and is notable for combining classic file-infection behavior with modular post-compromise functionality. High-confidence reporting links it to the Maze gang, a major ransomware operation that also developed or operated Maze, Egregor, and Sekhmet-related tooling. The malware’s role within that ecosystem suggests use in intrusion support, payload delivery, and remote control on compromised Windows systems.
C2 tracking
Derp observations, rolling seven-day window
Samples
3863464e29728c1bc9e472132fbb13b532f895a46fce8a66c59c1e8012b42a55 6ff8480cde0b319de96e500d451ae2b892acf35d7635d560d4afacbee4960a58 b19d304f847edbe2581176c316fb9f35111aca6e14a9fa1c752c8089b07b4189 b2660a2e88514b6fe1ff2f776c96ab852b0ce563c5a2258a199a2eb2bdb19a1d d9d63d41ca11d527ff6d6fcb6e4f332dd3648cfd93127de99050776d9f963a99 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.