HackerFeeds
All ransomware groups

maze

59 tracked victims
·first seen 2019-10-21·last activity 2020-09-11

Group profile

Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers believed that Maze operates as an affiliated network model. MAZE was one of the first groups that made a 'Double Extortion Attack' involved Allied Universal, in November 2019, the group leaks their victim's data in the darknet. On November 1, 2020, MAZE announced an official press release that they are closing their operation. is malware targeting organizations worldwide across many industries. Security researchers claim that the threat actor behind the MAZE group is 'TA2101'.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1189Drive-by Compromise

    Maze distributed via exploit kits (Fallout EK, Spelevo EK) through malvertising campaigns and compromised websites.

  • T1190Exploit Public-Facing Application

    Exploitation of Pulse Secure VPN and Citrix ADC (CVE-2019-19781) vulnerabilities to gain initial access.

  • T1566.001Phishing: Spearphishing Attachment

    Maze used malicious Word documents with macros delivered via phishing emails as a primary initial access vector.

TA0002

Execution

  • T1059.001Command and Scripting Interpreter: PowerShell

    PowerShell used for payload delivery, lateral movement, and post-exploitation tasks.

  • T1203Exploitation for Client Execution

    Browser and plugin vulnerabilities exploited via exploit kits to execute the Maze payload on victim endpoints.

TA0005

Defense Evasion

  • T1218.011Signed Binary Proxy Execution: Rundll32

    Rundll32 used to load malicious DLLs and bypass application control solutions.

  • T1562.001Disable or Modify Tools

    Security software terminated and disabled using batch scripts prior to ransomware deployment.

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    Mimikatz deployed to harvest credentials from LSASS memory.

TA0007

Discovery

  • T1018Remote System Discovery

    Active Directory enumeration to identify all hosts within the domain for maximum encryption coverage.

  • T1046Network Service Discovery

    Network scanning to enumerate hosts and services for lateral movement.

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP used for lateral movement across the network with harvested credentials.

  • T1021.002Remote Services: SMB/Windows Admin Shares

    PsExec and SMB shares used to propagate the Maze payload to remote systems.

TA0010

Exfiltration

  • T1567Exfiltration Over Web Service

    Maze pioneered the double extortion model — among the first ransomware groups to exfiltrate data before encryption and publish it on a dedicated leak site ('Maze News') to pressure victims into paying.

TA0011

Command and Control

  • T1071.001Application Layer Protocol: Web Protocols

    Cobalt Strike used for C2 communications over HTTPS.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Maze uses ChaCha20 for file encryption with RSA-2048 for key protection. Active 2019-2020, Maze was the pioneer of the double extortion model that became the ransomware industry standard. The group formally announced retirement in November 2020; affiliates migrated to Egregor.

  • T1490Inhibit System Recovery

    Volume Shadow Copies removed; Windows Backup catalog deleted to prevent recovery.

Recent victims

showing 50 of 59
DateWebsite / victimSectorCountry
2020-09-11
F
Fairfax County Public Schools
EducationUS
2020-09-08
T
Toledo Public Schools (TPS)
EducationUS
2020-09-01
A
Artech Information Systems
TechnologyUS
2020-08-05
C
Canon
ManufacturingUS
2020-08-01
S
SK Hynix (semiconductor company)
Manufacturing
2020-07-25
S
Strata Plus (strata management firm)
Business ServicesAU
2020-07-05
X
X-FAB
ManufacturingUS
2020-07-01
T
Thai Beverage Public Company
Agriculture and Food ProductionTH
2020-06-29
O
Ostermeir FZE (engineering firm)
ManufacturingAE
2020-06-28
V
VirtualGuard
Public SectorUS
2020-06-25
xerox.com
Xerox Corporationxerox.com
TechnologyGB
2020-06-10
A
Ahmed Almazrouei Group
Manufacturing
2020-06-10
W
Westmoreland Mechanical Testing and Research, Inc.
ManufacturingUS
2020-06-10
O
Omnix Int'l
TechnologyAE
2020-06-10
F
FERSPED Inc. (Macedonian shipping company)
Transportation/Logistics
2020-06-10
D
Daily Thermetrics
ManufacturingUS
2020-06-10
M
Munoz Engineering PC
ManufacturingUS
2020-06-10
D
Domingos Martins
Public SectorBR
2020-06-10
J
John Christner Trucking
Transportation/LogisticsUS
2020-06-10
M
Mead O'Brien, Inc
ManufacturingUS
2020-06-10
U
United Enertech (US construction company
ConstructionUS
2020-06-08
C
Collabera
TechnologyUS
2020-06-01
W
Westech International (US military contractor)
Public SectorUS
2020-06-01
C
Columbus Metro Federal Credit Union
Financial ServicesUS
2020-06-01
W
Webuild SpA (industrial group)
ManufacturingIT
2020-06-01
W
WorldNet Telecommunications and ISP
TelecommunicationPR
2020-06-01
F
Faxon Machining
ManufacturingUS
2020-06-01
E
Electricity Generating Authority of Thailand
EnergyTH
2020-06-01
L
LG Electronics
Technology
2020-05-29
C
Conducent
TechnologyUS
2020-05-24
M
Max Linear (radio- frequency chip maker)
TelecommunicationUS
2020-05-09
P
Pitney Bowes
TechnologyUS
2020-05-07
H
HLB (Belgian accounting firm)
Financial ServicesBE
2020-05-05
P
Plastic Surgeon Kristin Tarbet (Bellevue, Wash)
HealthcareUS
2020-05-05
A
Ashville Plastic Surgery Institute
HealthcareUS
2020-05-01
S
Sparboe (egg producer)
Agriculture and Food ProductionUS
2020-05-01
B
Banco BCR
Financial ServicesCR
2020-04-26
D
Dakota Carrier Network (DCN)
TechnologyUS
2020-04-25
T
Tom Berkowitz Trucking Inc (whitinsville, MA)
Transportation/LogisticsUS
2020-04-20
B
Benefit Recovery Specialists Inc (BRSI)
Financial ServicesUS
2020-04-17TechnologyUS
2020-04-05
S
Southeastern Wire (wire manufacturer)
ManufacturingUS
2020-04-01
B
Berkine (Algerian Petroleum Joint Venture)
EnergyDZ
2020-04-01
C
Chubb
Financial ServicesUS
2020-03-15
H
Henning Harders (freight and logistics firm)
Transportation/LogisticsAU
2020-03-14
H
Hammersmith Medicines Research
Business ServicesGB
2020-03-07
V
VT San Antonio Aerospace (aerospace and defense contractor)
ManufacturingUS
2020-02-01
A
Affordacare Urgent Care Clinic
HealthcareUS
2020-02-01
C
CU Collections
Business ServicesUS
2020-02-01
A
Affordacare Urgent Care Clinics
HealthcareUS