Skip to content

M0yv

M0yv is a modular x86/x64 Windows file-infector malware associated with the Maze ransomware ecosystem.

Profile source: Mallory opens in a new tab

M0yv

Family profile

M0yv is a modular x86/x64 Windows file-infector malware associated with the Maze ransomware ecosystem. It targets Portable Executable files on Windows and has been described as a file-infecting virus that can extend beyond simple parasitic infection to function as a dropper and remote access trojan. Publicly discussed source code attributed to the Maze operation indicates that M0yv formed part of that group’s broader tooling arsenal.

A notable feature of M0yv is its domain generation algorithm, which produces pseudo-random command-and-control domains from embedded seeds. Research on the malware’s DGA and subsequent sinkholing activity indicates that M0yv used algorithmically generated domains to support resilient network communications and hinder straightforward infrastructure blocking. This behavior aligns with its use as a backdoor-capable platform rather than a purely destructive or self-contained file infector.

M0yv is primarily a Windows threat and is notable for combining classic file-infection behavior with modular post-compromise functionality. High-confidence reporting links it to the Maze gang, a major ransomware operation that also developed or operated Maze, Egregor, and Sekhmet-related tooling. The malware’s role within that ecosystem suggests use in intrusion support, payload delivery, and remote control on compromised Windows systems.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 3, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • AU1

Leading providers

  • Hyonix1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

M0yv in ATT&CK

10 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.