Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When redirected to the exploit, Spelevo will attempt to exploit the critical CVE-2018-15982 use after free vulnerability in the browser, with users of Flash Player versions 31.0.0.153 / 31.0.0.108 and earlier being the ones exposed. Upon successful exploitation, the exploit kit will automatically download and install the Maze Ransomware payload via arbitrary code execution. | The Spelevo exploit kit has been spotted by security researchers while infecting victims with Maze Ransomware payloads via a new malicious campaign that exploits a Flash Player use after free vulnerability.
A100-509 - Exploit Kit Activity - Fallout Exploit Kit CVE-2018-8174, Github PoC A100-339 - Exploit Kit Activity - Fallout Exploit Kit CVE-2018-8174, Landing Page
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Weak RDP credentials on machines accessible from the internet also pose a threat as the operators of Maze may use this flaw as well.
The distribution tactic of the Maze ransomware initially involved infections via exploit kits (namely, Fallout EK and Spelevo EK), as well as via spam with malicious attachments.
The servers were vulnerable to the CVE-2019-19781 vulnerability, which Mursch described as "Maze's favorite vector of compromise."
After the company refused to cough up the 300 Bitcoin ($2.3 million) ransom, the attackers threatened to use sensitive information extracted from Allied Universal’s systems, as well as stolen email and domain name certificates, for a spam campaign impersonating the company.
Once the virtual machine was started... a batch file called startup_vrun.bat batch file would be executed that preps the machine with the Maze executables.
If they fall for it, the malicious macro contained inside the document will execute, which in turn will result in the victim’s PC being infected with Maze ransomware.
If the recipient opens the attached document, they will be prompted to enable editing mode and then enable the content. If they fall for it, the malicious macro contained inside the document will execute, which in turn will result in the victim’s PC being infected with Maze ransomware.
It employs various tricks to hinder static analysis, including dynamic API function imports, control flow obfuscation using conditional jumps, replacing RET with JMP dword ptr [esp-4], replacing CALL with PUSH + JMP, and several other techniques.
The Maze ransomware is typically distributed as a PE binary (EXE or DLL depending on the specific scenario) which is developed in C/C++ and obfuscated by a custom protector.
To counter dynamic analysis, this Trojan will also terminate processes typically used by researchers, e.g. procmon, procexp, ida, x32dbg, etc.
During these stages, the use of the following tools has been observed: mimikatz, procdump, Cobalt Strike, Advanced IP Scanner, Bloodhound, PowerSploit, and others.
Cybercriminals are embracing data-theft extortion by creating dark web marketplaces that exist solely to sell stolen data.
Before encrypting a victim's network, most network-targeting ransomware operations will steal a victim's unencrypted files.
Before deploying ransomware, the Maze operators always steal unencrypted files before encrypting them. | Cognizant can confirm that a security incident involving our internal systems, and causing service disruptions for some of our clients, is the result of a Maze ransomware attack.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that encrypts victim systems and, prior to encryption, exfiltrates data to increase extortion leverage by threatening or conducting public data leaks if ransom demands are not met.
Ransomware that is delivered via exploit kits, encrypts documents, photos, databases, and other files using RSA and the ChaCha20 stream cipher, drops a ransom note named DECRYPT-FILES.txt, and directs victims to TOR/clear-web payment and support portals.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.