Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers believed that Maze operates as an affiliated network model. MAZE was one of the first groups that made a 'Double Extortion Attack' involved Allied Universal, in November 2019, the group leaks their victim's data in the darknet. On November 1, 2020, MAZE announced an official press release that they are closing their operation. is malware targeting organizations worldwide across many industries. Security researchers claim that the threat actor behind the MAZE group is 'TA2101'. Known victims: 59 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Maze is a prominent ransomware threat group known for their double extortion attacks, where they demand payment not only for decrypting files but also for preventing the leak of stolen data. They have targeted organizations globally across various industries and are notable for their affiliate model and high-profile campaigns.

Goals & Targeting

Maze's primary goals are financial gain through ransom payments and organizational disruption. Their targeting profile is broad, with victims drawn from various sectors globally. The group's choice of targets often reflects opportunities for easy monetization, with a focus on industries where data breaches could have significant reputational and financial consequences, such as healthcare and education.

Enhanced Description

Maze ransomware group is one of the most notorious cybercriminal groups active since at least October 2019. The group operates a double extortion model, where victims are threatened with both file encryption and data leaks if they do not pay the demanded ransom. Maze gained infamy when they targeted AlliedUniversal in November 2019, marking one of the earliest instances of double extortion. The group's operational approach involves encrypting victim files and then exfiltrating sensitive data, which is shared publicly on darknet forums unless a ransom is paid. In November 2020, Maze announced an official press release stating they were ceasing operations, possibly due to increasing pressure from law enforcement. Despite this apparent shutdown, the group's tactics have influenced other ransomware operators, solidifying their place as trailblazers in the cybercrime landscape.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Oct 21, 2019
Last Seen
Sep 11, 2020
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.