Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Aug 28, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Maze is a human-operated Windows ransomware family first observed in 2019 and widely recognized for popularizing the double-extortion model in which operators steal data before encrypting systems and threaten public disclosure if victims refuse to pay.
Profile source: Mallory opens in a new tabMaze
Maze is a human-operated Windows ransomware family first observed in 2019 and widely recognized for popularizing the double-extortion model in which operators steal data before encrypting systems and threaten public disclosure if victims refuse to pay. It has been associated with attacks against large enterprises and organizations across sectors including healthcare, technology, manufacturing, logistics, legal services, engineering, and government-related entities.
Maze has been delivered through multiple intrusion paths, including spam and spearphishing attachments, exploitation of internet-facing vulnerabilities, exposed remote access services, and follow-on deployment after earlier compromise. Reporting also describes Maze as commonly used as a secondary-stage payload by affiliates after initial access, particularly in intrusions involving exposed RDP and broader hands-on-keyboard activity.
Technically, Maze uses a staged architecture in which a loader decrypts and launches the main ransomware module in memory. Public analyses describe layered payload decryption and extensive anti-analysis measures, including debugger interference through patching of DbgUiRemoteBreakin, API indirection, kill-switch logic, and language-based execution exclusions that avoid systems configured for Russia and several CIS-region locales. The malware enumerates processes, gathers host and security-product information, terminates selected applications and services to free locked files, deletes shadow copies to hinder recovery, and encrypts files on local drives and accessible network shares. It also drops ransom notes broadly, can alter the desktop wallpaper, and has been observed using synthesized speech to deliver extortion messages to victims.
Maze operators and affiliates have used scheduled tasks for timed execution and have delivered components via MSI packages executed with msiexec. Affiliate tradecraft has included use of red-team frameworks and post-compromise tooling for reconnaissance, credential theft, privilege escalation, lateral movement, and persistence before ransomware deployment. Maze activity has also been linked in reporting to a custom loader commonly referred to as DllCrypt.
Operationally, Maze became notable for maintaining a public leak site used to shame victims and publish stolen data, and it later cooperated with other ransomware operations through shared leak-platform activity sometimes described as a cartel model. The group was also among ransomware actors reported to escalate pressure through direct phone harassment of victims. Maze is generally regarded as one of the most influential ransomware operations in the evolution of modern extortion-centric crimeware.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
"305419896": "Ryuk/TrickBot/Maze/EvilCorp/Pyxie/APT41 - Stats uniques -> ips/hostnames: 344 publickeys: 200"
Maze ransomware doesn’t just demand payment for a decryptor but exfiltrates victim data and threatens to leak it publicly if the target doesn’t pay up.
La campagne d’attaques délivrant Egregor serait liée à la fin d’activité du groupe d’attaquants à l’origine du rançongiciel Maze.
According to Callow, the security incident was a data-stealing ransomware attack launched by the Maze ransomware group. Maze not only spreads across a network, infecting and encrypting every computer in its path, it also exfiltrates the data to the attackers’ servers where it is held for ransom.
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
"Since November 2019, we’ve seen the MAZE ransomware being used in attacks that combine targeted ransomware use, public exposure of victim data, and an affiliate model."
"...TA551 IcedID implants were associated with Maze and Egregor ransomware events in 2020."
In July 2020, Mandiant observed UNC2198 leverage network access provided by an ICEDID infection to encrypt an environment with MAZE ransomware.
Exploited software
MITRE ATT&CK
Reporting
Maze emerged as one of the most influential ransomware operations targeting businesses, corporations, and municipal organizations, combining file encryption with data theft and public leak threats to force victims into paying. The group first spread through exploit kits and malicious spam, then shifted to more targeted intrusions using spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and attacks against weak RDP credentials. Researchers described Maze as a C/C++ Windows PE malware with obfuscation, anti-analysis features, and a layered encryption scheme that paired ChaCha with RSA-2048. The operation also expanded its influence by forming a ransomware cartel with LockBit and RagnarLocker, sharing leak infrastructure and tradecraft in a model that helped normalize double-extortion tactics across the broader ransomware ecosystem.
eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.
ProLock ransomware was used in targeted intrusions against organizations after attackers gained access through QakBot, phishing campaigns, and exposed or compromised RDP services. Reporting linked ProLock to the earlier PwndLocker family and described it as the final stage of a broader compromise in which operators conducted reconnaissance, abused legitimate Windows processes, and used batch scripts, Task Scheduler, and PowerShell to deploy the encryptor across victim environments. Once executed, ProLock disabled processes and services, deleted shadow copies, and encrypted files larger than 8,192 bytes while leaving the first 8,192 bytes intact before appending the .prolock extension and dropping ransom notes. The campaign drew additional scrutiny after the FBI warned that some victims who paid received a faulty decryptor that corrupted files instead of restoring them, underscoring both the operational risk of payment and the likelihood that data theft could accompany the encryption phase.
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.
Fresenius, Europe’s largest private hospital operator, disclosed a ransomware incident that disrupted parts of its global technology environment while saying patient care continued. Reporting on the attack cited Snake ransomware as the likely cause, a strain associated with targeting large enterprises and stealing unencrypted files before locking systems. The company said it detected a computer virus, activated containment measures, and notified authorities, but did not provide technical details or say whether it would pay a ransom. Honda also investigated network disruptions in Europe and Japan that were widely linked to SNAKE/EKANS ransomware. Researchers said a malware sample appeared tailored for Honda, checking for the internal domain mds.honda.com and referencing an IP tied to the company, indicating deliberate targeting rather than opportunistic spread. The incidents unfolded amid broader warnings from INTERPOL that cybercriminals were intensifying ransomware attacks against critical healthcare institutions, underscoring how Snake operators were pursuing both industrial and healthcare organizations.
Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.