maze logo

maze

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: ChaCha
Ver en IntelTracker → APTTrail →
Maze ransomware emerged in May 2019, initially identified as 'ChaCha ransomware,' and quickly distinguished itself by pioneering the double extortion technique. This method involved not only encrypting victims' data but also exfiltrating sensitive information and threatening its public release if a ransom was not paid. Operating with an affiliate-based model, Maze operators also maintained a dedicated public-facing website, 'Maze News,' to list victims and publish stolen data, significantly increasing pressure on organizations. While the group claimed to officially cease operations in November 2020, its tactics and a potential rebranding have been observed in subsequent ransomware variants like Egregor and Sekhmet. The group's primary motivation was financial gain through extortion, and it is assessed with high confidence to be of Russian origin, indicated by its malware avoiding systems configured with Russian or former Soviet Union languages.
Malware asociado
WannaCry, Qbot, Remcos RAT, Ursnif, Remcos RAT, CHOPSTICK
Tecnicas MITRE
T1133, T1583, T1560, T1105, T1588, T1003
CVEs relacionadas
CVE-2020-0787

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaBrazilCanadaChinaGermanyFranceUnited KingdomHong Kong

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesCredit UnionsSoftware PublishersEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com