Twisted Spider is a financially motivated cybercriminal extortion group best known for operating the Maze ransomware program and for its close association with the related Sekhmet and Egregor ransomware families. The group is widely tracked as the operator behind the Maze-to-Sekhmet-to-Egregor lineage and is notable for popularizing large-scale data-theft extortion in ransomware operations, helping drive the broader adoption of leak-site pressure tactics across the eCrime ecosystem. Twisted Spider conducted big-game-hunting intrusions against organizations judged able to pay substantial ransoms, including repeated targeting of healthcare entities and other enterprises in the United States, as well as victims in France. Reported victim sectors include healthcare, government, financial services, energy, manufacturing, technology, telecommunications, media, retail, aviation, academia, automotive, and other business environments. The group has also been linked to attacks affecting video game companies through Egregor activity. Operationally, Twisted Spider used double-extortion tactics: stealing sensitive data before encrypting systems, then threatening public disclosure if payment was not made. Maze and Egregor both maintained leak-site style pressure operations, and Egregor additionally threatened broader dissemination of stolen data through forums, darknet venues, torrents, and media exposure. Egregor was operated as a ransomware-as-a-service offering, with multiple affiliates or intrusion sets able to deploy the payload. Observed intrusion chains associated with Twisted Spider included phishing with malicious macro documents, abuse of exposed or illicitly obtained RDP access, and use of upstream malware such as QakBot, Ursnif, and IcedID for initial access and foothold development. The group and its affiliates used common post-compromise tooling including Cobalt Strike, PsExec, AdFind, SharpHound, PowerShell, bitsadmin, and Rclone. Reported behaviors include Active Directory reconnaissance, lateral movement via administrative access and SMB beacons, data exfiltration to cloud storage, process injection, reflective DLL injection, anti-debugging and code obfuscation, attempts to disable Windows Defender through Group Policy changes, and deletion of shadow copies to inhibit recovery. Twisted Spider has documented ties within the ransomware ecosystem. Reporting has linked the group to the so-called Maze Cartel and to data-sharing or operational relationships involving LockBit and other criminal actors. Additional reporting associates TA2101 with Twisted Spider and notes that other eCrime groups leveraged IcedID to provide initial access for Twisted Spider-linked ransomware deployments. Microsoft has also tracked the actor cluster as Storm-0216 in financially motivated activity. The group announced the end of the Maze project on 1 November 2020, after which activity shifted to Egregor. Later reporting stated that Maze, Sekhmet, and Egregor were all operated by the same actor set. Some reporting mentions Ukrainian nationals among participants, while other reporting characterizes the group as international; high-confidence public reporting most directly supports a Ukrainian nexus rather than a formal state affiliation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat actor tracked by Microsoft as a Storm cluster.
Listed as part of a broader 'Ransom Cartel/Maze Cartel' collection of criminals (per cited reporting) that use ransomware for extortion; no further specifics in this content.
Organized cybercriminal cluster associated with Maze, Egregor, and Sekhmet ransomware operations targeting enterprises including game developers for extortion and data theft.
Operates the Maze ransomware/doxware scheme, encrypting business victims’ data and stealing data before encryption to pressure victims through public leaks and extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.