Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers believed that Maze operates as an affiliated network model. MAZE was one of the first groups that made a 'Double Extortion Attack' involved Allied Universal, in November 2019, the group leaks their victim's data in the darknet. On November 1, 2020, MAZE announced an official press release that they are closing their operation. is malware targeting organizations worldwide across many industries. Security researchers claim that the threat actor behind the MAZE group is 'TA2101'. Known victims: 59 1 ransom note(s) on file
Objectives
Executive Summary
Maze is a prominent ransomware threat group known for their double extortion attacks, where they demand payment not only for decrypting files but also for preventing the leak of stolen data. They have targeted organizations globally across various industries and are notable for their affiliate model and high-profile campaigns.
Goals & Targeting
Maze's primary goals are financial gain through ransom payments and organizational disruption. Their targeting profile is broad, with victims drawn from various sectors globally. The group's choice of targets often reflects opportunities for easy monetization, with a focus on industries where data breaches could have significant reputational and financial consequences, such as healthcare and education.
Enhanced Description
Maze ransomware group is one of the most notorious cybercriminal groups active since at least October 2019. The group operates a double extortion model, where victims are threatened with both file encryption and data leaks if they do not pay the demanded ransom. Maze gained infamy when they targeted AlliedUniversal in November 2019, marking one of the earliest instances of double extortion. The group's operational approach involves encrypting victim files and then exfiltrating sensitive data, which is shared publicly on darknet forums unless a ransom is paid. In November 2020, Maze announced an official press release stating they were ceasing operations, possibly due to increasing pressure from law enforcement. Despite this apparent shutdown, the group's tactics have influenced other ransomware operators, solidifying their place as trailblazers in the cybercrime landscape.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics