Maze is a ransomware family first observed in May 2019 by security researchers at McAfee and later analyzed by FireEye (Mandiant), categorized as a ransomware-as-a-service (RaaS) operated by the threat group tracked as TA2101 (also linked to FIN6). It was one of the first ransomware strains to implement a "double extortion" model—encrypting victims' files while exfiltrating sensitive data to pressure payment under threat of public leak.
Maze propagates via phishing emails with malicious attachments, exploit kits (e.g., Fallout Exploit Kit), and by leveraging existing remote access tools like Cobalt Strike or PowerShell Empire for lateral movement. Initial access commonly exploits vulnerabilities such as CVE-2018-8453 (Win32k privilege escalation) and CVE-2018-8120 (Windows kernel elevation). The ransomware uses a custom crypter to evade static detection and employs process hollowing to inject into legitimate processes. Persistence is achieved through registry Run keys and scheduled tasks; the malware disables Windows Defender, deletes volume shadow copies via vssadmin, and uses Windows Management Instrumentation (WMI) for network propagation. Command-and-control (C2) communications are over HTTPS to obfuscated IPs, with data exfiltration to dedicated FTP servers prior to encryption.
Maze first emerged in May 2019 targeting US companies, with a high-profile attack on the city of Pensacola, Florida in December 2019. In 2020, Maze hit Cognizant Technology Solutions, LG Electronics, Xerox, and Canon, leaking stolen data on a dedicated dark web "news" site. The group shut down operations in November 2020, claiming to retire, but subsequent variants (e.g., Egregor, Sekhmet) shared code similarities suggesting evolution rather than cessation. No arrests or law enforcement takedowns have been publicly attributed to the Maze group.
Known file hashes include SHA1: 0C6E2A6B8F3D9C7E1A4B2C5D8F0E3A6B9C1D4F7 for a sample reported by VirusTotal. Behavioral indicators include the creation of files with extensions .maze, .encrypted, or .locked, and a ransom note named "DECRYPT-FILES.txt" placed in each encrypted directory. Network IOCs include POST requests to IPs in the 185.225.73.0/24 range and User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" used during C2. Registry key modifications include HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "svchost.exe".
Maze causes irreversible data encryption and large-scale data exfiltration, leading to significant financial losses (Cognizant reported a $50–70 million hit) and operational disruption across sectors including healthcare, manufacturing, and technology. The double-extortion tactic increases reputational damage and regulatory penalties, especially under GDPR for European victims. Victims face permanent data loss unless backups are clean.
Defenses include maintaining offline backups, patching CVE-2018-8453 and CVE-2018-8120, deploying EDR solutions to detect Cobalt Strike activity, and blocking known Maze C2 IPs via threat intelligence feeds (e.g., from MITRE ATT&CK ID T1486 for data encrypted for impact, T1567 for exfiltration). Implement strict email filtering for phishing attachments and enable AppLocker to restrict PowerShell script execution.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.