Maze, also known as Maze Crew and Maze Team, was a financially motivated ransomware operation first observed in May 2019. Its operators and affiliates compromised enterprise and public-sector networks, stole sensitive information, and encrypted files to demand ransom payments. Maze pioneered and popularized double extortion in late 2019, threatening to publish stolen information alongside demands for decryption. Its dedicated leak site named non-paying victims and published documents, databases, and other evidence of compromise. Maze targeted organizations across multiple industries, including industrial manufacturing, transportation, engineering, information technology services, healthcare, insurance, utilities, legal services, and government. Documented targeting included organizations in the United States, Brazil, North Macedonia, and the United Arab Emirates. Initial-access methods included phishing and spearphishing with malicious Office documents, exploit kits, exposed RDP services, brute-force attacks, SMB exploitation, and exploitation of known vulnerabilities, including Pulse Secure VPN vulnerability CVE-2019-11510. Affiliates used Cobalt Strike, Metasploit, PowerShell Empire, Mimikatz, AdFind, and other administrative or offensive-security tools for reconnaissance, credential theft, privilege escalation, persistence, and lateral movement. One affiliate, tracked as SNOW, maintained multiple backdoors, scanned SMB and RDP services, used pass-the-hash techniques, and concealed Cobalt Strike activity through process injection. Maze deployments also used a custom loader known as DllCrypt and Windows Installer packages executed through the signed Windows Installer utility. The ransomware encrypted files and deleted shadow copies to inhibit recovery. Maze wound down its operation in 2020, and many of its affiliates subsequently moved to Egregor. Affiliate migration connected the two ecosystems without establishing that they were the same organization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Popularized double-extortion ransomware by publishing stolen victim data when victims refused payment.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Conducting ransomware-driven extortion campaigns that encrypt victim files, exfiltrate data, and threaten public leaks if victims do not pay; also publicly naming non-compliant victims.
A ransomware group referenced as collaborating or sharing tooling with Conti, including negotiations, code access, and overlap in the Academi intrusion set.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.