Skip to content

Maze

Maze is a human-operated Windows ransomware family first observed in 2019 and widely recognized for popularizing the double-extortion model in which operators steal data before encrypting systems and threaten public disclosure if victims refuse to pay.

Profile source: Mallory opens in a new tab

Maze

Family profile

Maze is a human-operated Windows ransomware family first observed in 2019 and widely recognized for popularizing the double-extortion model in which operators steal data before encrypting systems and threaten public disclosure if victims refuse to pay. It has been associated with attacks against large enterprises and organizations across sectors including healthcare, technology, manufacturing, logistics, legal services, engineering, and government-related entities.

Maze has been delivered through multiple intrusion paths, including spam and spearphishing attachments, exploitation of internet-facing vulnerabilities, exposed remote access services, and follow-on deployment after earlier compromise. Reporting also describes Maze as commonly used as a secondary-stage payload by affiliates after initial access, particularly in intrusions involving exposed RDP and broader hands-on-keyboard activity.

Technically, Maze uses a staged architecture in which a loader decrypts and launches the main ransomware module in memory. Public analyses describe layered payload decryption and extensive anti-analysis measures, including debugger interference through patching of DbgUiRemoteBreakin, API indirection, kill-switch logic, and language-based execution exclusions that avoid systems configured for Russia and several CIS-region locales. The malware enumerates processes, gathers host and security-product information, terminates selected applications and services to free locked files, deletes shadow copies to hinder recovery, and encrypts files on local drives and accessible network shares. It also drops ransom notes broadly, can alter the desktop wallpaper, and has been observed using synthesized speech to deliver extortion messages to victims.

Maze operators and affiliates have used scheduled tasks for timed execution and have delivered components via MSI packages executed with msiexec. Affiliate tradecraft has included use of red-team frameworks and post-compromise tooling for reconnaissance, credential theft, privilege escalation, lateral movement, and persistence before ransomware deployment. Maze activity has also been linked in reporting to a custom loader commonly referred to as DllCrypt.

Operationally, Maze became notable for maintaining a public leak site used to shame victims and publish stolen data, and it later cooperated with other ransomware operations through shared leak-platform activity sometimes described as a cartel model. The group was also among ransomware actors reported to escalate pressure through direct phone harassment of victims. Maze is generally regarded as one of the most influential ransomware operations in the evolution of modern extortion-centric crimeware.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Aug 28, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • NL1

Leading providers

  • TechTies Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

14 named in public reporting
TA2101

CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.

APT28

CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.

APT29

CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.

APT41

"305419896": "Ryuk/TrickBot/Maze/EvilCorp/Pyxie/APT41 - Stats uniques -> ips/hostnames: 344 publickeys: 200"

Maze

Maze ransomware doesn’t just demand payment for a decryptor but exfiltrates victim data and threatens to leak it publicly if the target doesn’t pay up.

Twisted Spider

La campagne d’attaques délivrant Egregor serait liée à la fin d’activité du groupe d’attaquants à l’origine du rançongiciel Maze.

Maze Ransomware

According to Callow, the security incident was a data-stealing ransomware attack launched by the Maze ransomware group. Maze not only spreads across a network, infecting and encrypting every computer in its path, it also exfiltrates the data to the attackers’ servers where it is held for ransom.

FIN7

In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.

DEV-0216

In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.

Lockean

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

OnePercent

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

FIN6

"Since November 2019, we’ve seen the MAZE ransomware being used in attacks that combine targeted ransomware use, public exposure of victim data, and an affiliate model."

TA551

"...TA551 IcedID implants were associated with Maze and Egregor ransomware events in 2020."

UNC2198

In July 2020, Mandiant observed UNC2198 leverage network access provided by an ICEDID infection to encrypt an environment with MAZE ransomware.

Exploited software

Vulnerabilities linked to Maze

8 CVEs

MITRE ATT&CK

Maze in ATT&CK

84 distinct techniques

Techniques

84 techniques
T1486 Data Encrypted for Impact T1059.003 Windows Command Shell T1033 System Owner/User Discovery T1491.001 Internal Defacement T1070 Indicator Removal T1566 Phishing T1027.003 Steganography T1027 Obfuscated Files or Information T1047 Windows Management Instrumentation T1071.001 Web Protocols T1135 Network Share Discovery T1574 Hijack Execution Flow T1518 Software Discovery T1190 Exploit Public-Facing Application T1497.001 System Checks T1082 System Information Discovery T1567 Exfiltration Over Web Service T1622 Debugger Evasion T1620 Reflective Code Loading T1057 Process Discovery T1614.001 System Language Discovery T1489 Service Stop T1564.004 NTFS File Attributes T1598.004 Spearphishing Voice T1218.007 Msiexec T1053.005 Scheduled Task T1210 Exploitation of Remote Services T1218 System Binary Proxy Execution T1547 Boot or Logon Autostart Execution T1485 Data Destruction T1074 Data Staged T1055 Process Injection T1568 Dynamic Resolution T1547.001 Registry Run Keys / Startup Folder T1003 OS Credential Dumping T1133 External Remote Services T1048 Exfiltration Over Alternative Protocol T1566.001 Spearphishing Attachment T1046 Network Service Discovery T1106 Native API T1059 Command and Scripting Interpreter T1021 Remote Services T1041 Exfiltration Over C2 Channel T1105 Ingress Tool Transfer T1078 Valid Accounts T1021.002 SMB/Windows Admin Shares T1657 Financial Theft T1068 Exploitation for Privilege Escalation T1530 Data from Cloud Storage T1021.001 Remote Desktop Protocol T1537 Transfer Data to Cloud Account T1110 Brute Force T1567.002 Exfiltration to Cloud Storage T1583 Acquire Infrastructure T1497 Virtualization/Sandbox Evasion T1490 Inhibit System Recovery T1562 Impair Defenses T1027.007 Dynamic API Resolution T1071 Application Layer Protocol T1199 Trusted Relationship T1567.003 Exfiltration to Text Storage Sites T1189 Drive-by Compromise T1539 Steal Web Session Cookie T1204.002 Malicious File T1203 Exploitation for Client Execution T1112 Modify Registry T1059.001 PowerShell T1484 Domain or Tenant Policy Modification T1583.003 Virtual Private Server T1036 Masquerading T1562.001 Disable or Modify Tools T1529 System Shutdown/Reboot T1053 Scheduled Task/Job T1140 Deobfuscate/Decode Files or Information T1136 Create Account T1083 File and Directory Discovery T1204 User Execution T1202 Indirect Command Execution T1614 System Location Discovery T1564.006 Run Virtual Instance T1055.001 Dynamic-link Library Injection T1036.004 Masquerade Task or Service T1049 System Network Connections Discovery T1027.016 Junk Code Insertion

Reporting

Research mentioning Maze

Jul 17
Sentinelone Labs

Maze Ransomware Update: Extorting and Exposing Victims - SentinelLabs

Maze emerged as one of the most influential ransomware operations targeting businesses, corporations, and municipal organizations, combining file encryption with data theft and public leak threats to force victims into paying. The group first spread through exploit kits and malicious spam, then shifted to more targeted intrusions using spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and attacks against weak RDP credentials. Researchers described Maze as a C/C++ Windows PE malware with obfuscation, anti-analysis features, and a layered encryption scheme that paired ChaCha with RSA-2048. The operation also expanded its influence by forming a ransomware cartel with LockBit and RagnarLocker, sharing leak infrastructure and tradecraft in a model that helped normalize double-extortion tactics across the broader ransomware ecosystem.

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

Jan 1
Sophos Threat Research

ProLock ransomware gives you the first 8 kilobytes of decryption for free | SOPHOS

ProLock ransomware was used in targeted intrusions against organizations after attackers gained access through QakBot, phishing campaigns, and exposed or compromised RDP services. Reporting linked ProLock to the earlier PwndLocker family and described it as the final stage of a broader compromise in which operators conducted reconnaissance, abused legitimate Windows processes, and used batch scripts, Task Scheduler, and PowerShell to deploy the encryptor across victim environments. Once executed, ProLock disabled processes and services, deleted shadow copies, and encrypted files larger than 8,192 bytes while leaving the first 8,192 bytes intact before appending the .prolock extension and dropping ransom notes. The campaign drew additional scrutiny after the FBI warned that some victims who paid received a faulty decryptor that corrupted files instead of restoring them, underscoring both the operational risk of payment and the likelihood that data theft could accompany the encryption phase.

Mar 22
Sentinelone Labs Subdomain

Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs

SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.

Oct 28
Picus Security

A Detailed Walkthrough of Ranzy Locker Ransomware TTPs

Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.

Sep 2
Sentinelone Labs Subdomain

New Snake Ransomware Adds Itself to the Increasing Collection of Golang Crimeware - SentinelLabs

Fresenius, Europe’s largest private hospital operator, disclosed a ransomware incident that disrupted parts of its global technology environment while saying patient care continued. Reporting on the attack cited Snake ransomware as the likely cause, a strain associated with targeting large enterprises and stealing unencrypted files before locking systems. The company said it detected a computer virus, activated containment measures, and notified authorities, but did not provide technical details or say whether it would pay a ransom. Honda also investigated network disruptions in Europe and Japan that were widely linked to SNAKE/EKANS ransomware. Researchers said a malware sample appeared tailored for Honda, checking for the internal domain mds.honda.com and referencing an IP tied to the company, indicating deliberate targeting rather than opportunistic spread. The incidents unfolded amid broader warnings from INTERPOL that cybercriminals were intensifying ransomware attacks against critical healthcare institutions, underscoring how Snake operators were pursuing both industrial and healthcare organizations.

Sep 2
Sentinelone Labs Subdomain

Ranzy Ransomware | Better Encryption Among New Features of ThunderX Derivative - SentinelLabs

May 13
Securelist

Evolution of JSWorm ransomware | Securelist

Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.