Credential Theft
- Mimikatz
- ProcDump
Maze is a Windows ransomware family first observed in May 2019, previously known as ChaCha ransomware.
Profile source: Mallory opens in a new tabMaze
Maze is a Windows ransomware family first observed in May 2019, previously known as ChaCha ransomware. It was used in targeted, human-operated intrusions and is notable for popularizing double extortion: operators stole victim data before encrypting files, then threatened public disclosure through a leak platform if payment was withheld. Maze targeted enterprises and government-linked organizations across numerous sectors, including technology, healthcare, legal services, insurance, logistics, engineering, energy, and manufacturing. The operation also collaborated with other ransomware groups on shared data-leak infrastructure.
Maze has been delivered through malicious spam attachments, exploitation of vulnerabilities, network intrusion, exposed Remote Desktop Protocol services, fake websites, and exploit kits. It can use MSI packages executed through the signed Windows Installer utility. Affiliates have used credential dumping, network and RDP scanning, SMB-based movement, remote execution tooling, and Cobalt Strike during intrusions before ransomware deployment.
The malware uses a loader that decrypts and reflectively loads its main DLL payload from data concealed in an embedded image resource. It incorporates anti-analysis measures, including debugger-attachment interference and obfuscated API invocation, and avoids execution on systems configured for Russian and various CIS-region language settings. Maze enumerates processes and installed security products, terminates selected security, analysis, database, and business-application processes, deletes volume shadow copies, and encrypts local and network-share files using ChaCha-based cryptography. It stores key-related material in NTFS extended attributes, distributes ransom notes, changes the desktop wallpaper, and can play synthesized spoken ransom messages. It also establishes scheduled-task persistence and communicates host, operating-system, network, and security-product details to operator-controlled infrastructure. Maze’s victim portal supports victim identification, negotiation chat, and test decryption.
Reported operators
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
"305419896": "Ryuk/TrickBot/Maze/EvilCorp/Pyxie/APT41 - Stats uniques -> ips/hostnames: 344 publickeys: 200"
Maze ransomware doesn’t just demand payment for a decryptor but exfiltrates victim data and threatens to leak it publicly if the target doesn’t pay up.
La campagne d’attaques délivrant Egregor serait liée à la fin d’activité du groupe d’attaquants à l’origine du rançongiciel Maze.
According to Callow, the security incident was a data-stealing ransomware attack launched by the Maze ransomware group. Maze not only spreads across a network, infecting and encrypting every computer in its path, it also exfiltrates the data to the attackers’ servers where it is held for ransom.
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
"Since November 2019, we’ve seen the MAZE ransomware being used in attacks that combine targeted ransomware use, public exposure of victim data, and an affiliate model."
"...TA551 IcedID implants were associated with Maze and Egregor ransomware events in 2020."
In July 2020, Mandiant observed UNC2198 leverage network access provided by an ICEDID infection to encrypt an environment with MAZE ransomware.
Exploited software
MITRE ATT&CK
Reporting
Maze emerged as one of the most influential ransomware operations targeting businesses, corporations, and municipal organizations, combining file encryption with data theft and public leak threats to force victims into paying. The group first spread through exploit kits and malicious spam, then shifted to more targeted intrusions using spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and attacks against weak RDP credentials. Researchers described Maze as a C/C++ Windows PE malware with obfuscation, anti-analysis features, and a layered encryption scheme that paired ChaCha with RSA-2048. The operation also expanded its influence by forming a ransomware cartel with LockBit and RagnarLocker, sharing leak infrastructure and tradecraft in a model that helped normalize double-extortion tactics across the broader ransomware ecosystem.
eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.
ProLock ransomware was used in targeted intrusions against organizations after attackers gained access through QakBot, phishing campaigns, and exposed or compromised RDP services. Reporting linked ProLock to the earlier PwndLocker family and described it as the final stage of a broader compromise in which operators conducted reconnaissance, abused legitimate Windows processes, and used batch scripts, Task Scheduler, and PowerShell to deploy the encryptor across victim environments. Once executed, ProLock disabled processes and services, deleted shadow copies, and encrypted files larger than 8,192 bytes while leaving the first 8,192 bytes intact before appending the .prolock extension and dropping ransom notes. The campaign drew additional scrutiny after the FBI warned that some victims who paid received a faulty decryptor that corrupted files instead of restoring them, underscoring both the operational risk of payment and the likelihood that data theft could accompany the encryption phase.
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.
Fresenius, Europe’s largest private hospital operator, disclosed a ransomware incident that disrupted parts of its global technology environment while saying patient care continued. Reporting on the attack cited Snake ransomware as the likely cause, a strain associated with targeting large enterprises and stealing unencrypted files before locking systems. The company said it detected a computer virus, activated containment measures, and notified authorities, but did not provide technical details or say whether it would pay a ransom. Honda also investigated network disruptions in Europe and Japan that were widely linked to SNAKE/EKANS ransomware. Researchers said a malware sample appeared tailored for Honda, checking for the internal domain mds.honda.com and referencing an IP tied to the company, indicating deliberate targeting rather than opportunistic spread. The incidents unfolded amid broader warnings from INTERPOL that cybercriminals were intensifying ransomware attacks against critical healthcare institutions, underscoring how Snake operators were pursuing both industrial and healthcare organizations.
Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.