Maze
MITRE ATT&CK: S0449 View on attack.mitre.org
Aliases: ChaCha, Maze
- First seen
- 2019-05-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 36 (35 malicious)
- Last IoC activity
- 2026-08-29 20:19:19
- Profile updated
- 2026-07-07 12:38:45
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications retail-and-hospitality manufacturing
Context
Maze ransomware, previously known as "ChaCha", was discovered in May 2019. In addition to encrypting files on victim machines for impact, Maze operators conduct information stealing campaigns prior to encryption and post the information online to extort affected companies.
Recent IoC activity
35 malicious indicators in Maltiverse are attributed to Maze (S0449). The 20 most recently updated:
Detection coverage
- 4 YARA rules
- 565 Sigma rules
Malware & tools used
- Junk Code Insertion (attack-pattern)
- System Information Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- System Language Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Run Virtual Instance (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Native API (attack-pattern)
- Web Protocols (attack-pattern)
- Windows Command Shell (attack-pattern)
- Scheduled Task (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Process Discovery (attack-pattern)
- Indicator Removal (attack-pattern)
- Service Stop (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Msiexec (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
Used by threat actors
Detection rules
- ARKBIRD_SOLG_Ran_Egregor_Oct_2020_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Maze (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Ransomware_Maze (yara-rule)
- SIGNATURE_BASE_Crime_Win32_Ransom_Maze_Dll_1 (yara-rule)
Related threat objects
- Ragnar Locker (malware)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- proofpoint.com — Ta2101 Plays Government Imposter Distribute Malware German Italian And Us (report)
- CrowdStrike — Twisted Spider (report)
- analyst1.com — Ransom Mafia Analysis Of The World%E2%80%99S First Ransomware Cartel (report)
- secureworks.com — Gold Village (report)
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — Ransomware Preparedness A Call To Action (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 2 (report)
- analyst1.com — Ransom Mafia Analysis Of The Worlds First Ransomware Cartel (report)
- statescoop.com — Baltimore Ransomware Crowdstrike Extortion (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- domaintools.com — The Most Prolific Ransomware Families A Defenders Guide (report)
- blog.redteam.pl — Sodinokibi Revil Ransomware (report)
- blog.sensecy.com — Global Ransomware Attacks In 2020 The Top 4 Vulnerabilities (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- cti-league.com — Cti League Darknet Report 2021 (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- Microsoft — Microsoft Digital Defense Report 2020 September (report)
- ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
- ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
- ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
- krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)