Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When redirected to the exploit, Spelevo will attempt to exploit the critical CVE-2018-15982 use after free vulnerability in the browser, with users of Flash Player versions 31.0.0.153 / 31.0.0.108 and earlier being the ones exposed. Upon successful exploitation, the exploit kit will automatically download and install the Maze Ransomware payload via arbitrary code execution. | The Spelevo exploit kit has been spotted by security researchers while infecting victims with Maze Ransomware payloads via a new malicious campaign that exploits a Flash Player use after free vulnerability.
A100-509 - Exploit Kit Activity - Fallout Exploit Kit CVE-2018-8174, Github PoC A100-339 - Exploit Kit Activity - Fallout Exploit Kit CVE-2018-8174, Landing Page
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Past Maze infections have been traced back to exploit kits, unsecured remote desktop connections, impersonation emails and compromised email accounts via malicious Word documents.
The distribution tactic of the Maze ransomware initially involved infections via exploit kits (namely, Fallout EK and Spelevo EK), as well as via spam with malicious attachments.
Maze tends to use known vulnerabilities like the Pulse VPN CVE-2019-11510 to break in
Maze Ransomware usually deploy phishing emails with MS Office attachments and fake/phishing websites laced with Exploit Kits.
The threat actor group APT28 leverages TTPs like obfuscated files or information, PowerShell
If they fall for it, the malicious macro contained inside the document will execute, which in turn will result in the victim’s PC being infected with Maze ransomware.
The threat actor group APT28 leverages TTPs like obfuscated files or information
During these stages, the use of the following tools has been observed: mimikatz, procdump, Cobalt Strike, Advanced IP Scanner, Bloodhound, PowerSploit, and others.
Before encrypting a victim's network, most network-targeting ransomware operations will steal a victim's unencrypted files.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that encrypts victim systems and, prior to encryption, exfiltrates data to increase extortion leverage by threatening or conducting public data leaks if ransom demands are not met.
Ransomware that is delivered via exploit kits, encrypts documents, photos, databases, and other files using RSA and the ChaCha20 stream cipher, drops a ransom note named DECRYPT-FILES.txt, and directs victims to TOR/clear-web payment and support portals.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.