Maze was a high-profile financially motivated ransomware operation active from 2019 until its reported shutdown in late 2020. It is widely recognized for popularizing double extortion: stealing victim data before encryption and threatening public release if ransom demands were not met. The group operated dedicated victim negotiation infrastructure and a public leak site, sometimes referred to as Maze News, and used public exposure, media engagement, and reputational pressure as part of its extortion model. Known aliases and related references include Maze Team, Maze ransomware operators, Maze ransomware affiliates, and earlier identification as ChaCha ransomware. Reporting also links Maze’s ecosystem to affiliates and to later overlap or migration involving Egregor and Sekhmet. Maze infections were delivered through multiple intrusion vectors over time, including exploit kits, spam campaigns, Remote Desktop Protocol compromise, and broader network exploitation. The operation evolved from broader distribution to more targeted intrusions associated with big-game hunting. Observed tradecraft included persistence establishment, anti-analysis checks, system and network reconnaissance, data exfiltration prior to encryption, deletion of shadow copies, and selective file and directory targeting during encryption. Technical analyses describe heavy obfuscation, dynamic API resolution, anti-debugging logic, command-line switches, and use of RSA together with ChaCha20 for file encryption. Maze also used alternative remote-access channels in some intrusions, including RDP tunneled through Ngrok. Maze’s extortion model combined encryption with theft-based coercion and public leak-site operations. The group published stolen data from non-paying victims and threatened staged releases to increase pressure. It is repeatedly cited as one of the earliest and most influential operators to normalize leak-site-backed ransomware extortion, a model later adopted across the ransomware ecosystem by groups such as REvil, DoppelPaymer, Clop, LockBit, and others. Maze also reportedly offered to host leaked data for other criminal groups lacking their own leak portals, further reinforcing its role in shaping extortion tactics. Victim reporting and public cases tie Maze to attacks against large enterprises and public-sector entities, including technology, manufacturing, staffing, and government organizations. Named victims include Canon, LG Electronics, Xerox, Southwire, Allied Universal, and the City of Pensacola. The group conducted data theft in addition to encryption and used victim-specific negotiation and pressure tactics, including deadlines, staged publication, and claims of deleting stolen data after payment. Maze publicly claimed some targeting restraints during the COVID-19 period, including statements about pausing attacks on medical organizations, but it remained a major ransomware threat. Maze is also relevant as part of a broader criminal ecosystem. Reporting indicates affiliates and initial-access actors participated in its operations, with revenue sharing between access providers, deploying affiliates, and developers. Multiple sources state that many Maze affiliates later moved to Egregor as Maze wound down, and some researchers assessed strong code or operational lineage between Maze, Egregor, and Sekhmet. Maze’s historical significance lies less in novel encryption alone than in institutionalizing leak-site-driven double extortion as a standard ransomware practice.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware group in connection with a rumored 2020 breach of Cognizant (parent company of TriZetto). No linkage to the 2024–2025 TriZetto incident is asserted in the content.
Referenced as a double-extortion ransomware operator used as a comparison point for DarkSide’s business model and tactics.
Ransomware operation known for targeted intrusions and pioneering public data-leak extortion, including publishing stolen victim data and using media attention to pressure victims into paying.
Named as a ransomware group that FIN7 is known to collaborate with (no specific activity described in this content).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.