Maze was a financially motivated ransomware operation active from 2019 until it shut down in 2020. Also known as the Maze Crew or Maze Team, it was among the first ransomware operations to popularize double extortion: affiliates stole sensitive data before encrypting victim systems, then threatened to publish the data through a public leak site if the victim did not pay. The operation targeted enterprises and public-sector organizations across multiple sectors, including information technology, engineering and industrial services, utilities, and municipal government. Maze commonly functioned as the final payload in multi-stage intrusions. Initial access was obtained through phishing and spearphishing, exposed Remote Desktop Protocol services, brute-force activity, exploitation of vulnerable internet-facing systems, and SMB-related techniques. Affiliates used tools including Cobalt Strike, Mimikatz, Metasploit, PowerShell, AdFind, and PsExec for reconnaissance, credential theft, privilege escalation, lateral movement, and deployment. A documented affiliate tracked as SNOW used a custom loader alongside red-team tooling, established backdoors when administrative access was unavailable, and waited for privileged users to authenticate before continuing the intrusion. Maze operators and affiliates conducted network and account discovery, harvested credentials, scanned internal systems and RDP services, accessed network shares, and exfiltrated data before encryption. They also impaired recovery by deleting shadow copies and targeting backup infrastructure. Maze used signed-binary proxy execution through Windows Installer in some campaigns and used process injection to conceal Cobalt Strike activity. Its leak-site model publicly named non-paying victims and released samples of stolen data, creating reputational and regulatory pressure in addition to operational disruption. Following Maze's closure, multiple affiliates reportedly moved to the Egregor ransomware-as-a-service operation. Maze has also been associated with broader eCrime ecosystem overlaps involving TrickBot, Zloader, and Gozi, although such overlaps do not establish that these operations were a single organization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Popularized double-extortion ransomware by publishing stolen victim data when victims refused payment.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Conducting ransomware-driven extortion campaigns that encrypt victim files, exfiltrate data, and threaten public leaks if victims do not pay; also publicly naming non-compliant victims.
A ransomware group referenced as collaborating or sharing tooling with Conti, including negotiations, code access, and overlap in the Academi intrusion set.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.