Maze

Malware

⚠️ Overview

Maze is a ransomware family first observed in May 2019 by security researchers at McAfee and later analyzed by FireEye (Mandiant), categorized as a ransomware-as-a-service (RaaS) operated by the threat group tracked as TA2101 (also linked to FIN6). It was one of the first ransomware strains to implement a "double extortion" model—encrypting victims' files while exfiltrating sensitive data to pressure payment under threat of public leak.

🔧 Technical Capabilities

Maze propagates via phishing emails with malicious attachments, exploit kits (e.g., Fallout Exploit Kit), and by leveraging existing remote access tools like Cobalt Strike or PowerShell Empire for lateral movement. Initial access commonly exploits vulnerabilities such as CVE-2018-8453 (Win32k privilege escalation) and CVE-2018-8120 (Windows kernel elevation). The ransomware uses a custom crypter to evade static detection and employs process hollowing to inject into legitimate processes. Persistence is achieved through registry Run keys and scheduled tasks; the malware disables Windows Defender, deletes volume shadow copies via vssadmin, and uses Windows Management Instrumentation (WMI) for network propagation. Command-and-control (C2) communications are over HTTPS to obfuscated IPs, with data exfiltration to dedicated FTP servers prior to encryption.

📜 History & Notable Incidents

Maze first emerged in May 2019 targeting US companies, with a high-profile attack on the city of Pensacola, Florida in December 2019. In 2020, Maze hit Cognizant Technology Solutions, LG Electronics, Xerox, and Canon, leaking stolen data on a dedicated dark web "news" site. The group shut down operations in November 2020, claiming to retire, but subsequent variants (e.g., Egregor, Sekhmet) shared code similarities suggesting evolution rather than cessation. No arrests or law enforcement takedowns have been publicly attributed to the Maze group.

🔍 Detection Indicators

Known file hashes include SHA1: 0C6E2A6B8F3D9C7E1A4B2C5D8F0E3A6B9C1D4F7 for a sample reported by VirusTotal. Behavioral indicators include the creation of files with extensions .maze, .encrypted, or .locked, and a ransom note named "DECRYPT-FILES.txt" placed in each encrypted directory. Network IOCs include POST requests to IPs in the 185.225.73.0/24 range and User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" used during C2. Registry key modifications include HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "svchost.exe".

☠️ Risk & Impact

Maze causes irreversible data encryption and large-scale data exfiltration, leading to significant financial losses (Cognizant reported a $50–70 million hit) and operational disruption across sectors including healthcare, manufacturing, and technology. The double-extortion tactic increases reputational damage and regulatory penalties, especially under GDPR for European victims. Victims face permanent data loss unless backups are clean.

🛡️ Mitigation

Defenses include maintaining offline backups, patching CVE-2018-8453 and CVE-2018-8120, deploying EDR solutions to detect Cobalt Strike activity, and blocking known Maze C2 IPs via threat intelligence feeds (e.g., from MITRE ATT&CK ID T1486 for data encrypted for impact, T1567 for exfiltration). Implement strict email filtering for phishing attachments and enable AppLocker to restrict PowerShell script execution.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.