Maze was a financially motivated ransomware operation active from 2019 through late 2020 that became widely known for pioneering large-scale double-extortion ransomware. In addition to encrypting victim systems, Maze operators and affiliates stole data and threatened public disclosure through a dedicated leak site, establishing a coercive model later adopted across the ransomware ecosystem. The operation is commonly referred to as Maze, Maze Team, Maze Crew, or Maze ransomware, and reporting has linked its later evolution and affiliate migration to Egregor and, in some accounts, Sekhmet. Maze functioned as an affiliate-driven crimeware operation rather than a single intrusion set. Affiliates used multiple initial-access vectors, including phishing and spearphishing, exposed RDP, brute force, and SMB exploitation, then relied heavily on commodity and red-team tooling for post-compromise activity. Observed tooling associated with Maze intrusions includes Cobalt Strike, PowerShell, Metasploit, AdFind, Koadic, Empire, GMER, and Mimikatz. Documented behaviors include reconnaissance, credential theft, privilege escalation, persistence through multiple backdoors, lateral movement via SMB, RDP, network shares, and PsExec, and process injection to conceal beacon activity. Maze components were also delivered through MSI packages executed with msiexec, and affiliates used a custom loader commonly called DllCrypt. Maze campaigns typically involved multi-stage intrusions in which ransomware deployment occurred after substantial hands-on-keyboard activity. Affiliates mapped networks, scanned internal and external targets, waited for privileged logons when necessary, and then encrypted systems while also exfiltrating sensitive data for extortion. The group publicly shamed non-paying victims by listing them on its leak site and publishing samples or larger portions of stolen data. Maze was also associated with threats to abuse stolen information in follow-on pressure campaigns. Reporting on backup-focused extortion tradecraft indicates Maze actors sought cloud and backup credentials, restored victim data to attacker-controlled infrastructure for theft, and deleted backups before encryption. Victimology shows broad targeting across private-sector and public-sector organizations, including IT services, legal services, medical and healthcare entities, insurance, staffing, transportation, manufacturing, distributors and resellers, and government-related organizations. Named victims and reporting indicate activity affecting organizations in the United States, Germany, Italy, Poland, France, Canada, and Japan. Maze was repeatedly described as one of the most dangerous and actively developed ransomware frameworks of its period. Maze’s influence extended beyond its own campaigns. It is widely credited as the first ransomware operation to normalize double extortion at scale, and later groups such as Egregor, REvil, Conti, and others adopted similar pressure tactics. Reporting also indicates overlap between Maze affiliates and other eCrime ecosystems, including TrickBot, Gozi, Zloader, and IcedID. Multiple reports state that many Maze affiliates shifted to Egregor after Maze announced its shutdown in late 2020, and some reporting has linked individuals associated with Maze leadership to Egregor as well.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Conducting ransomware-driven extortion campaigns that encrypt victim files, exfiltrate data, and threaten public leaks if victims do not pay; also publicly naming non-compliant victims.
A ransomware group referenced as collaborating or sharing tooling with Conti, including negotiations, code access, and overlap in the Academi intrusion set.
Referenced as a ransomware group in connection with a rumored 2020 breach of Cognizant (parent company of TriZetto). No linkage to the 2024–2025 TriZetto incident is asserted in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.