Maze is a Windows ransomware family first observed in May 2019 and previously known as ChaCha ransomware. Its financially motivated operators popularized double extortion in late 2019 by stealing organizational data before encryption and publishing stolen information when victims refused to pay. Maze attacks affected enterprises across multiple industries, including healthcare, technology services, engineering, transportation, and energy. The operation shut down in 2020.
Maze uses ChaCha-family symmetric encryption and RSA to render victim files inaccessible. It can enumerate and encrypt files on local storage and network shares, terminate selected business applications to release files, and delete Volume Shadow Copies to impede recovery. It distributes ransom notes, changes the desktop wallpaper, and can repeatedly play synthesized spoken ransom demands. Its victim portal supports operator chat and test decryption.
Analyzed variants use an executable loader containing an encrypted DLL concealed within an embedded PNG resource. Multiple decoding and decryption stages recover the payload for execution in memory; Maze has also used DLL injection into another process. Defense-evasion features include obfuscated Windows API invocation, termination of analysis tools, and modification of a debugger-attachment routine to prevent debugging. Some variants avoid execution on systems configured with Russian and several other regional language settings. Maze gathers and transmits host, operating-system, network, and installed-antivirus information.
Delivery and intrusion methods include malicious spam attachments, phishing, exploit kits, vulnerability exploitation, and deployment after network compromise. FIN7 activity has preceded Maze attacks, and intrusions attributed to Gold Melody, also tracked as UNC961 and Prophet Spider, have preceded Maze deployment by distinct follow-on actors. These precursor relationships do not establish that those groups operated Maze itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
Maze tends to use known vulnerabilities like the Pulse VPN CVE-2019-11510 to break in and this means employees working from home must be mindful when accessing sensitive company information. | CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
Example actor leveraging Metasploit for SMB scanning: use auxiliary/scanner/smb/smb_ms17_010
The Windows Background Intelligent Transfer Service (BITS) is vulnerable to a privilege elevation vulnerability if it improperly handles symbolic links... The exploit was used in Maze and Egregor ransomware campaigns. | The exploit was used in Maze and Egregor ransomware campaigns.
The servers were vulnerable to the CVE-2019-19781 vulnerability, which Mursch described as "Maze's favorite vector of compromise." | The operators of the Maze ransomware have published today tens of GB of internal data from the networks of enterprise business giants LG and Xerox following two failed extortion attempts.
Maze Ransomware now uses the Spelevo exploit kit in a new malicious campaign using a Flash Player vulnerability to attack users. When redirected to Spelevo, the exploit kit will attempt to use vulnerability CVE-2018-15982. Vulnerable users are Flash Player versions 31.0.0.153 / 31.0.0.108 and earlier. After successful exploitation, the exploit kit automatically downloads and installs the Maze Ransomware payload. | Maze Ransomware Aliases: Maze Locker, MazeLocker, ChaCha, ChaChaLocker ... Этот крипто-вымогатель шифрует данные бизнес-пользователей и компаний с помощью RSA + ChaCha20 ... Вымогатели, распространяющие Maze, могут публиковать украденные данные с целью усиления давления на жертву.
"Since November 2019, we’ve seen the MAZE ransomware being used in attacks that combine targeted ransomware use, public exposure of victim data, and an affiliate model."
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This is part of a tactic known as double extortion, which was pioneered by the Maze ransomware group in late 2019.
The threat actor acting as a precursor for Maze and Ryuk ransomware attacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks.
"305419896": "Ryuk/TrickBot/Maze/EvilCorp/Pyxie/APT41 - Stats uniques -> ips/hostnames: 344 publickeys: 200"
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
179 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legacy ransomware family that ceased operations in 2020; public decryption assistance may exist for certain older variants.
Ransomware family credited with popularizing the double-extortion model by publicly releasing stolen victim data following non-payment.
Referenced as another ransomware family that combines encryption with data extortion/publication pressure.
Ransomware first observed in May 2019 that encrypts files, drops ransom notes, deletes shadow copies to inhibit recovery, and exfiltrates victim data for double-extortion by threatening public leaks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.