India’s Cyber Swachhta Kendra issued an alert on Maze ransomware, following McAfee Labs’ publication on the threat. Maze became known for double extortion: attackers stole sensitive information before encrypting victims’ files, then threatened to publish the stolen data to pressure organizations into paying. This approach made ransomware incidents both operational disruptions and potential data breaches.
Organizations defending against Maze should prioritize tested, isolated backups, timely patching, strong authentication for remote access, and monitoring for unauthorized data transfers and mass file changes. Incident-response plans should address data exposure alongside system recovery: restoring encrypted systems does not resolve the risk from stolen information. Suspected infections warrant rapid isolation of affected systems, preservation of evidence, and assessment of any notification obligations.

TTPs, infrastructure, and targeting history in one profile.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.