Maze

MITRE ATT&CK: S0449 View on attack.mitre.org

Aliases: ChaCha, Maze

First seen
2019-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
36 (35 malicious)
Last IoC activity
2026-08-29 20:19:19
Profile updated
2026-07-07 12:38:45

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications retail-and-hospitality manufacturing

Context

Maze ransomware, previously known as "ChaCha", was discovered in May 2019. In addition to encrypting files on victim machines for impact, Maze operators conduct information stealing campaigns prior to encryption and post the information online to extort affected companies.

Recent IoC activity

35 malicious indicators in Maltiverse are attributed to Maze (S0449). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample da3b212d35c781ea49285ae21aad4d8f890857692b183b98b31fdf32f1a29718.exe 2026-08-29 2
file sample 333333333333333333.cmd 2026-08-28 1
file sample 2026-08-28_a773e3327bba2cb4a5031d682ed1f55c_bkransomware_elex_icedid_maze 2026-08-28 1
file sample 1bbdb22d5b359a65b2002322165514aae5374403ff5fd125a880cbc5b4a1a7f9 2026-08-26 1
file sample 44f19c91753f5ea8f3b24e4efb06f58544ca528a48cabfe2d1f84ce2b3296dc0 2026-08-26 1
file sample c5f21999e2041649b35637bb0ccbd321f9ef13b79ff1dabc02cde28c7c4678a5 2026-08-26 1
file sample _d482cac0754017ccc4e0f3b92c07f0ef4cd6dd394a6e3c7afe1fb928e487aa62.exe 2026-08-21 2
file sample 49b743fc85a2f5b83f079df8205ba3022cf1a3243bfd52b2b12be1e0e83572dc 2026-08-12 1
file sample c5a274e82cb2a04ae141cb224fd99d9b6602320b61eefb2d3e28f762f746ef3a 2026-08-08 1
file sample 59f3fdf16a7db80031ab151abc1c881a94ec26312b741579c2ed0cc4c0e501fe.bin 2026-08-04 2
file sample 1d1decac693bfc7c19e26f01929716924d7607e300f8385a7a8a02d176800db5 2026-07-28 1
URL https://download.cyberlearn.academy/download/download?url=https://files-ld.s3... 2026-07-17 1
file sample 9bca21b456b03e9a26cafe0becd3a546543ac7f5895fcea99b680f164e350ccd 2026-07-13 1
file sample 89c23ea47f094737756f1dde26444ece4fb4cf2e4eb7c6cb462e93fe5d6c4042 2026-07-08 1
file sample a7cf4a543e63b0547c9a568e6af640212012bc2627eacc13b41457ae644df141 2026-07-08 1
file sample daa4dbcccf9d44a832df373d4f9637e6979d53cba1adbaf42da246a8b7731b84.bin 2026-06-29 2
file sample 43abb0df3d1423e9323f8dc045bddde8990eecc9410d39a1f647200125da60f8.exe 2026-06-18 2
file sample fd9a7fa7cbcdf014c6610237a5d202a3f651bfdbd78a66b2f02726bbe14a5a50.bin 2026-06-11 2
file sample 2026-06-04_7db0303b62ca57f205705624d12742e4_glassworm_icedid_njrat_ryuk 2026-06-04 1
file sample e8a091a84dd2ea7ee429135ff48e9f48f7787637ccb79f6c3eb42f34588bc684.exe 2026-05-04 2

Detection coverage

  • 4 YARA rules
  • 565 Sigma rules

Malware & tools used

  • Junk Code Insertion (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • System Language Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Run Virtual Instance (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Native API (attack-pattern)
  • Web Protocols (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Process Discovery (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Service Stop (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Msiexec (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)

Used by threat actors

  • FIN6 (threat-actor)
  • FIN7 (threat-actor)

Detection rules

  • ARKBIRD_SOLG_Ran_Egregor_Oct_2020_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Maze (yara-rule)
  • DITEKSHEN_INDICATOR_KB_ID_Ransomware_Maze (yara-rule)
  • SIGNATURE_BASE_Crime_Win32_Ransom_Maze_Dll_1 (yara-rule)

Related threat objects

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
  • proofpoint.com — Ta2101 Plays Government Imposter Distribute Malware German Italian And Us (report)
  • CrowdStrike — Twisted Spider (report)
  • analyst1.com — Ransom Mafia Analysis Of The World%E2%80%99S First Ransomware Cartel (report)
  • secureworks.com — Gold Village (report)
  • CrowdStrike — Report2021Gtr (report)
  • CrowdStrike — Ransomware Preparedness A Call To Action (report)
  • CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 2 (report)
  • analyst1.com — Ransom Mafia Analysis Of The Worlds First Ransomware Cartel (report)
  • statescoop.com — Baltimore Ransomware Crowdstrike Extortion (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • domaintools.com — The Most Prolific Ransomware Families A Defenders Guide (report)
  • blog.redteam.pl — Sodinokibi Revil Ransomware (report)
  • blog.sensecy.com — Global Ransomware Attacks In 2020 The Top 4 Vulnerabilities (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • cti-league.com — Cti League Darknet Report 2021 (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • Microsoft — Microsoft Digital Defense Report 2020 September (report)
  • ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
  • ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
  • ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
  • krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)

External references