Description
Maze is a ransomware operation that pioneered data exfiltration and double extortion, publishing stolen files from victims who refused to pay. Its affiliates compromised large organizations through phishing, exploits, and purchased access, and its high profile attacks made ransomware a boardroom concern. The group announced its shutdown in late 2020, and its affiliates and tactics flowed into successor operations such as Egregor, a pattern that repeated across the industry.
Stats
- First seen
- February 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
23 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1027.016Junk Code Insertion
- T1027Obfuscated Files or Information
- T1027.016Junk Code Insertion
- T1036Masquerading
- T1036.004Masquerade Task or Service
- T1055Process Injection
- T1055.001Dynamic-link Library Injection
- T1070Indicator Removal
- T1218System Binary Proxy Execution
- T1218.007Msiexec
- T1564Hide Artifacts
- T1564.006Run Virtual Instance
TA0007 Discovery
TA0011 Command and Control
TA0040 Impact
TA0112 Defense Impairment
- T1685Disable or Modify Tools
Associated groups
Alert name variants
| Alert Name |
|---|
| DeepScan:Generic.Ransom.Maze.28646622 |
| DeepScan:Generic.Ransom.Maze.9C73E1EE |
| DeepScan:Generic.Ransom.Maze.D88EAA85 |
| Dump:Generic.Ransom.Maze.28646622 |
| Dump:Generic.Ransom.Maze.34659D46 |
| Dump:Generic.Ransom.Maze.9C73E1EE |
| Dump:Generic.Ransom.Maze.D88EAA85 |
| Gen:Variant.Ransom.Maze.11 |
| Gen:Variant.Ransom.Maze.2 |
| Gen:Variant.Ransom.Maze.5 |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-OTHER Win.Trojan.Maze variant download attempt |
