Netskope Threat Labs

Maze

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Maze is a ransomware operation that pioneered data exfiltration and double extortion, publishing stolen files from victims who refused to pay. Its affiliates compromised large organizations through phishing, exploits, and purchased access, and its high profile attacks made ransomware a boardroom concern. The group announced its shutdown in late 2020, and its affiliates and tactics flowed into successor operations such as Egregor, a pattern that repeated across the industry.

First seen
February 2022
Last seen
October 2026

23 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1049System Network Connections Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1614System Location Discovery

TA0011 Command and Control

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery
  • T1529System Shutdown/Reboot

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
DeepScan:Generic.Ransom.Maze.28646622
DeepScan:Generic.Ransom.Maze.9C73E1EE
DeepScan:Generic.Ransom.Maze.D88EAA85
Dump:Generic.Ransom.Maze.28646622
Dump:Generic.Ransom.Maze.34659D46
Dump:Generic.Ransom.Maze.9C73E1EE
Dump:Generic.Ransom.Maze.D88EAA85
Gen:Variant.Ransom.Maze.11
Gen:Variant.Ransom.Maze.2
Gen:Variant.Ransom.Maze.5