Overview

Platforms: Windows
Variants: Maze · ChaCha
Extensions: —
ATT&CK software: —
Initial access: Valid Accounts · External Remote Services
Top countries: —
Observed sectors: —

Attribution

TWISTED SPIDER VERIFIED
Vendor tracking name
CrowdStrike tracks TWISTED SPIDER as the criminal group responsible for developing and operating Maze ransomware.

Affiliates

No affiliate information available.

Activity

Recent Observations

Maze operation closes
November 2020
Operational closure
Maze announced that the project was officially closed and that new activity using its brand should be considered fraudulent.
Maze Cartel emerges
June 2020
Cybercrime collaboration
Maze infrastructure was used in a collaborative arrangement involving Maze, Ragnar Locker and LockBit operators.
Cognizant ransomware attack
April 2020
Major incident
Cognizant publicly confirmed that a disruptive security incident affecting its internal systems resulted from a Maze ransomware attack.
Double-extortion model
November 2019
Extortion evolution
Maze began publicly leaking stolen victim data, helping establish the data-theft-plus-encryption model later adopted widely across ransomware operations.

TTPs

ATT&CK coverage: 7 techniques · 7 tactics
T1078 Valid Accounts
VERIFIED
Initial Access / Persistence
Maze-related intrusions used valid accounts to gain or maintain access to victim environments.
T1133 External Remote Services
VERIFIED
Initial Access
Maze-related incidents included the use of externally accessible remote services.
T1059.001 PowerShell
VERIFIED
Execution
PowerShell was observed during Maze-related intrusion activity.
Show more TTPs (4)
T1003 OS Credential Dumping
VERIFIED
Credential Access
Credential dumping was observed during Maze-related intrusions.
T1018 Remote System Discovery
VERIFIED
Discovery
Maze-related operators performed remote system discovery inside compromised environments.
T1071.001 Web Protocols
VERIFIED
Command and Control
Maze communicated with hard-coded IP addresses over HTTP.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Maze encrypted files on victim systems using ChaCha-based and RSA cryptographic mechanisms.

Victims

Cognizant CONFIRMED
April 2020 United States Technology
Technology organization in United States.

CVEs

No CVE associations available.

Infrastructure

Maze leak site
Maze operated dedicated public leak infrastructure to publish stolen victim information and pressure organizations into paying ransoms.
Extortion infrastructure
Maze used its leak infrastructure as part of a double-extortion model combining data theft, encryption and public disclosure threats.

Timeline

2020-11
Maze officially closes
Maze announced the official closure of the project on November 1, 2020.
2020-06
Maze Cartel collaboration
Maze entered a documented collaborative arrangement involving Ragnar Locker and LockBit operators, including shared data-leak activity.
2020-04
Cognizant attack
Cognizant confirmed a disruptive Maze ransomware incident affecting its internal systems.
Show more events (2)
2019-11
Public data extortion begins
Maze began publicly releasing stolen victim data, helping establish double extortion as a major ransomware business model.
2019-05
Maze first observed
Maze ransomware, previously known as ChaCha, was first observed in May 2019.

Sources