Overview
Platforms:
Windows
Variants:
Maze · ChaCha
Extensions:
—
ATT&CK software:
—
Initial access:
Valid Accounts · External Remote Services
Top countries:
—
Observed sectors:
—
Attribution
TWISTED SPIDER
VERIFIED
Vendor tracking name
CrowdStrike tracks TWISTED SPIDER as the criminal group responsible for developing and operating Maze ransomware.
Affiliates
No affiliate information available.
Activity
Recent Observations
Maze operation closes
November 2020
Operational closure
Maze announced that the project was officially closed and that new activity using its brand should be considered fraudulent.
Maze Cartel emerges
June 2020
Cybercrime collaboration
Maze infrastructure was used in a collaborative arrangement involving Maze, Ragnar Locker and LockBit operators.
Cognizant ransomware attack
April 2020
Major incident
Cognizant publicly confirmed that a disruptive security incident affecting its internal systems resulted from a Maze ransomware attack.
Double-extortion model
November 2019
Extortion evolution
Maze began publicly leaking stolen victim data, helping establish the data-theft-plus-encryption model later adopted widely across ransomware operations.
TTPs
ATT&CK coverage:
7 techniques
· 7 tactics
T1078
Valid Accounts
VERIFIEDInitial Access / Persistence
Maze-related intrusions used valid accounts to gain or maintain access to victim environments.
T1133
External Remote Services
VERIFIEDInitial Access
Maze-related incidents included the use of externally accessible remote services.
T1059.001
PowerShell
VERIFIEDExecution
PowerShell was observed during Maze-related intrusion activity.
Show more TTPs (4)
T1003
OS Credential Dumping
VERIFIEDCredential Access
Credential dumping was observed during Maze-related intrusions.
T1018
Remote System Discovery
VERIFIEDDiscovery
Maze-related operators performed remote system discovery inside compromised environments.
T1071.001
Web Protocols
VERIFIEDCommand and Control
Maze communicated with hard-coded IP addresses over HTTP.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Maze encrypted files on victim systems using ChaCha-based and RSA cryptographic mechanisms.
Victims
Cognizant
CONFIRMED
Technology organization in United States.
CVEs
No CVE associations available.
Infrastructure
Maze leak site
Maze operated dedicated public leak infrastructure to publish stolen victim information and pressure organizations into paying ransoms.
Extortion infrastructure
Maze used its leak infrastructure as part of a double-extortion model combining data theft, encryption and public disclosure threats.
Timeline
2020-11
Maze officially closes
Maze announced the official closure of the project on November 1, 2020.
2020-06
Maze Cartel collaboration
Maze entered a documented collaborative arrangement involving Ragnar Locker and LockBit operators, including shared data-leak activity.
2020-04
Cognizant attack
Cognizant confirmed a disruptive Maze ransomware incident affecting its internal systems.
Show more events (2)
2019-11
Public data extortion begins
Maze began publicly releasing stolen victim data, helping establish double extortion as a major ransomware business model.
2019-05
Maze first observed
Maze ransomware, previously known as ChaCha, was first observed in May 2019.
Sources
Show more sources (5)
Cognizant Security Incident Update
Cognizant
Cognizant Technology Solutions — Form 8-K
U.S. Securities and Exchange Commission