The Maze ransomware operation evolved from earlier exploit-kit activity associated with “ChaCha ransomware” into a prominent double-extortion threat that stole data before encrypting systems and then pressured victims by publishing stolen files on dedicated leak sites. Operators built a public reputation around naming victims, courting media attention, and using data exposure as leverage to increase the likelihood of ransom payments.
Maze infections were delivered through multiple channels, including spam campaigns impersonating government tax agencies and later more targeted compromises through Remote Desktop Protocol (RDP) access and network exploitation. Sophos reported that the malware used heavy obfuscation, anti-analysis checks, persistence mechanisms, system and network reconnaissance, HTTP POST data exfiltration, and file encryption based on RSA and ChaCha20, while also showing selective behavior such as adjusting demands for home versus corporate systems and easing pressure in some medical-sector cases during COVID-19.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The report notes that during COVID-19, Maze at times avoided some medical targets and in certain cases reduced pressure, reflecting a selective operational approach.
According to Sophos, Maze later moved beyond broad delivery methods and conducted targeted intrusions using Remote Desktop Protocol access and network exploitation.
The report describes Maze being distributed through spam campaigns impersonating government tax agencies as part of its delivery evolution.
Sophos reports that Maze distinguished itself by publicizing victims and operating dedicated victim and leak sites to increase extortion pressure through public exposure.
The operation developed into Maze, a higher-profile ransomware brand that combined encryption with data theft and pressure tactics aimed at forcing victims to pay.
Sophos says the operation started under the earlier 'ChaCha ransomware' label and was initially delivered through exploit kits before evolving into the Maze brand.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.