Maze and Ragnar Locker were reported using increasingly sophisticated double-extortion tactics that combined data theft, public leak threats, and defense evasion during ransomware intrusions. Maze operators were linked to incidents including the attack on Cognizant and the publication of 2GB of allegedly stolen files from the City of Pensacola, underscoring that victims faced both operational disruption and potential data-breach exposure. Reporting also tied Maze to intrusion activity using exposed RDP, signed Cobalt Strike payloads, ngrok tunneling, remote execution with mshta, and tailored persistence mechanisms, with one investigated intrusion stopped before encryption was launched.
A key technical shift was the adoption of virtual-machine-based encryption to bypass endpoint defenses. In a Sophos-investigated case, Maze failed twice after security software blocked ransomware launched through scheduled tasks, then succeeded in deploying an MSI package that installed VirtualBox and a customized Windows 7 VM, mounted host drives, and encrypted files from inside the guest system. That approach mirrored Ragnar Locker, which had already used a smaller Windows XP VirtualBox image to make encryption appear to come from a trusted process while continuing its broader playbook of RDP-driven access, lateral movement, shadow-copy deletion, service termination, and Salsa20 plus RSA-2048 encryption backed by leak-site extortion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Symantec reported a ransomware intrusion in which attackers deployed a headless Windows 7 VirtualBox VM via a malicious MSI installer and likely ran the ransomware payload inside the guest to encrypt host files through shared folders. The payload was not conclusively identified, but artifacts suggested possible links to Conti, while Mount Locker was also observed on the same compromised machine.
The reference identifies Capcom as a victim of a Ragnar Locker ransomware attack. This adds a specific disclosed victim to the story beyond previously documented technical behavior and family background.
Securelist reports that Maze announced on November 1, 2020 that it had shut down.
Securelist states that Egregor was discovered in September 2020 as a newer ransomware family with code similarities to Sekhmet and Maze. It was described as typically deployed after a network breach as a password-protected DLL.
Securelist reported that Ragnar Locker publicly announced in July 2020 that it had joined the so-called 'Maze Cartel' distraction concept to cooperate in sharing and publishing victim data.
McAfee Labs reported on Ragnar Locker and highlighted that the ransomware operators threatened to release confidential information stolen from victims, documenting the group's use of data-leak extortion tactics. This adds an earlier explicit record of Ragnar Locker employing double-extortion behavior.
Acronis reported Ragnar Locker was first discovered in April 2020. The family was described as using double extortion and, in some cases, a VirtualBox Windows XP virtual machine to evade detection during encryption.
BleepingComputer reported that Ragnar Locker deliberately stopped services tied to backup, security, database, and remote management tools, including ConnectWise and Kaseya, to hinder detection and response. The report also said operators had begun using Ragnar Locker toward the end of December 2019 and threatened to leak stolen data if victims refused to pay.
The City of Pensacola was hit by a Maze ransomware attack earlier in December 2019, disrupting email, affecting some phone service, and forcing the shutdown of computer systems. The attackers allegedly stole data before encrypting the network and demanded $1 million for decryption.
Ragnar Locker ransomware was first observed in late 2019, marking the emergence of the Windows-targeting ransomware family. Later reporting also describes early variants as discovered in 2019.
After the failed attempts, Maze deployed an MSI installer that installed VirtualBox and a customized Windows 7 virtual machine, then encrypted host files from inside the guest by mounting host drives. Sophos identified this as adoption of a virtualization-based evasion technique previously associated with Ragnar Locker.
While responding to an incident, Sophos observed Maze attempt twice to deploy ransomware via scheduled tasks masquerading as security updates, but Sophos Intercept X blocked both attempts. The task names included variants such as 'Windows Update Security' and 'Google Chrome Security Update.'
During the same intrusion, the attackers established persistence through DLL hijacking on SolarWinds Orion RabbitMQ/Erlang components and, in another case, via a DLL loaded by Java Updater. They also used ngrok for tunneling, disabled UI0Detect, and moved laterally with sc.exe launching mshta to fetch HTA payloads.
In a SentinelLabs case study, a Maze affiliate intrusion against a U.S. company began on July 4 after attackers likely brute-forced the Administrator password on an internet-facing RDP system. They then uploaded a signed Cobalt Strike Beacon stager disguised as netplwiz.exe.
Cognizant later confirmed the incident was a Maze ransomware attack and said internal teams, external cyber defense firms, and law enforcement were involved in containment and response. It also continued providing clients with indicators of compromise and defensive technical information.
Cognizant disclosed that it suffered a cyberattack on a Friday night affecting internal systems and causing service disruptions for some clients. The company notified clients and shared preliminary indicators of compromise from its investigation.
Maze operators released 2GB of files they claimed were stolen from the City of Pensacola, saying the leak was meant to prove they exfiltrate substantial data during attacks. They claimed to have stolen 32GB in total and suggested further release would depend on circumstances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
id-ransomware.blogspot.com
Open sourcelabs.sentinelone.com
Open sourceblog.cyble.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcenews.sophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.