SNOW is a tracked Maze ransomware affiliate associated with enterprise intrusions that culminate in Maze deployment and extortion. The actor has been linked to the Maze ecosystem’s corporate ransomware model, including file encryption combined with threats based on stolen data. Reporting also places SNOW within a broader eCrime overlap zone involving tooling, infrastructure, or operational relationships connected to Zloader, Gozi, and TrickBot. SNOW’s operations emphasize post-compromise tradecraft typical of mature ransomware affiliates. Observed activity includes initial access via exposed RDP, brute force activity, and SMB exploitation, followed by extensive reconnaissance, credential theft, privilege escalation, lateral movement, and persistence. The actor has used common offensive and red-team tooling including Cobalt Strike, Metasploit, Mimikatz, PowerShell, AdFind, Koadic, PowerShell Empire, and GMER. Reconnaissance has included account and privilege enumeration, Kerberos ticket inspection, domain group discovery, network share enumeration, and internal port scanning. Credential access has included Mimikatz-based dumping and pass-the-hash. Lateral movement has involved PsExec, SMB-based movement, exploitation of reachable systems, and reuse of compromised hosts to scan for additional internal or external targets. A notable operational characteristic is patience after initial foothold. When administrative privileges were not immediately available, SNOW reportedly maintained multiple backdoors, mapped the environment, and waited for higher-privileged users to authenticate before pivoting toward higher-value assets such as domain controllers and other critical servers. Infections were sometimes left dormant for several days before follow-on activity resumed. SNOW has also been associated with a custom Maze loader commonly referred to as DllCrypt. Reverse engineering of this loader showed in-memory decryption and loading of the Maze ransomware payload, along with anti-analysis or defensive checks. Additional reporting linked packed delivery of the loader to a crypter associated with TrickBot customers and identified overlaps with Gozi and Zloader through certificate-chain and loader-trait pivots. These overlaps reinforce the assessment that SNOW operated within a fluid criminal ecosystem where affiliates and service providers reused malware delivery components, crypters, and access pathways across major crimeware families. Observed victim organizations included law firms, distributors, and resellers, indicating a focus on corporate environments where disruptive encryption and data-theft extortion could generate leverage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet operator/botmaster associated with controlling and operating the Aisuru/Kimwolf botnet, tied to proxy monetization and DDoS activity.
Named botmaster/operator associated with control of the Aisuru/Kimwolf botnet, involved in proxy-enabled abuse and DDoS operations; appears part of the same operator set as Dort.
Named botmaster/operator associated with controlling the Aisuru/Kimwolf botnet used for DDoS and residential proxy abuse; referenced alongside Dort as part of the current control of the botnet.
A profiled Maze affiliate operating attack servers and using Cobalt Strike and other tooling to gain access, persist, escalate privileges, move laterally, and ultimately support Maze ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.