Twisted Spider is a financially motivated extortion and ransomware threat actor best known for operating the Maze ransomware program and for its close association with the Sekhmet and Egregor ransomware families. The group is widely tracked in connection with the evolution of modern double-extortion ransomware, having adopted data-theft-and-leak pressure tactics in 2019 and helping normalize the use of dedicated leak infrastructure to coerce victims. Twisted Spider announced the end of the Maze project in November 2020, and reporting has consistently linked Maze, Sekhmet, and Egregor as part of the same operator lineage or closely connected set of operations. The actor has also been referenced as TA2101 and mapped by Microsoft as Storm-0216; UNC2198 has also been associated in reporting. Twisted Spider primarily targets organizations rather than consumers and has conducted big-game-hunting intrusions against enterprises assessed as able to pay large ransoms. Victimology associated with Maze and Egregor includes organizations in the United States and France, with especially notable impact on healthcare in 2020, as well as services and manufacturing. Reported sector targeting tied to Maze additionally spans government, financial services, energy, technology, telecommunications, media, retail, academia, aviation, healthcare, manufacturing, and automotive. Operationally, Twisted Spider has used both encryption and data theft for extortion. Maze, Sekhmet, and Egregor all employed file encryption alongside threats to publish stolen information if victims refused to negotiate. Egregor in particular operated as a ransomware-as-a-service offering, with affiliates and varying intrusion chains, while still showing strong continuity with Maze through code similarities, ransom-note overlap, shared tradecraft, and affiliate migration. Observed initial access and intrusion-enablement methods include phishing with malicious macro documents, abuse of exposed or illicitly obtained remote desktop access, and use of malware loaders or access brokers such as Qakbot, Ursnif, and IcedID. Reporting also notes affiliations in which other criminal actors leveraged IcedID to gain initial access for Twisted Spider-linked ransomware deployment. Post-compromise activity has included Active Directory reconnaissance with tools such as AdFind and SharpHound, lateral movement using PsExec and administrative access, use of Cobalt Strike for command and control and movement, PowerShell-based execution, exfiltration with RClone, and attempts to disable security controls through Group Policy changes. Technical behaviors associated with Egregor include reflective DLL injection, process injection, anti-debugging, code obfuscation, deletion of shadow copies, and language-based execution exclusions affecting multiple CIS-region locales. Twisted Spider is also associated with a broader ransomware ecosystem sometimes described as the Maze Cartel, with reported ties to actors behind LockBit and Viking Spider, including sharing of stolen victim data and extortion-related cooperation. The group’s activity is best characterized as criminal extortion for profit rather than state-directed espionage, although some reporting has described the operator set as international and noted references to Ukrainian nationals among participants.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat actor tracked by Microsoft as a Storm cluster.
Listed as part of a broader 'Ransom Cartel/Maze Cartel' collection of criminals (per cited reporting) that use ransomware for extortion; no further specifics in this content.
Ransomware and doxware operations distributing Sekhmet, encrypting corporate data and threatening to publish stolen data to pressure victims; later associated with Maze and Egregor operations.
Materially connected ransomware group described as collaborating with LockBit through shared victim data, infrastructure, and tactics in the so-called Ransom Cartel context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.