SentinelLabs profiled a Maze ransomware affiliate tracked as SNOW, detailing how the actor gained access mainly through exposed RDP services and SMB exploitation before deploying a custom Maze loader commonly called DllCrypt alongside tools including Cobalt Strike, Metasploit, and Mimikatz. Reverse engineering showed the loader used Sosemanuk encryption with hardcoded keying material to decrypt an in-memory loader and the final Maze payload, and included an AhnLab-themed killswitch file check. The investigation also linked the affiliate to wider eCrime activity through overlaps with Zloader, Gozi, and TrickBot, including shared certificates, crypter traits, and infrastructure patterns.
Mandiant’s reporting shows those findings fit Maze’s broader operating model as an affiliate-driven ransomware enterprise that shifted from early spam and exploit-kit delivery to post-compromise deployment, enabling network-wide encryption and double extortion through stolen-data leaks. Across incidents, Maze operators used credential theft, Active Directory reconnaissance, lateral movement over Cobalt Strike BEACON and RDP, and exfiltration through FTP, WinSCP, and cloud storage, while often dwelling in victim environments for weeks or months before encrypting high-value systems. The combined reporting depicts a patient, multi-stage intrusion model in which specialized actors obtained access, escalated privileges, mapped enterprise networks, stole data, and then launched Maze ransomware at scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs published a report profiling a MAZE ransomware affiliate tracked as SNOW. The report described the actor's tooling, infrastructure, loader design, and overlaps with Zloader, Gozi, and TrickBot ecosystems.
FireEye Mandiant published its analysis 'Navigating the MAZE: Tactics, Techniques and Procedures Associated With MAZE Ransomware Incidents.' The report detailed MAZE intrusion patterns, affiliate operations, victimology, and tooling.
Mandiant observed campaigns on November 18–19, 2019 targeting organizations in the United States and Canada. The lures included 'Missed package delivery' and 'Your AT&T wireless bill is ready to view' messages with malicious macro documents.
On November 8, 2019, Mandiant reported a MAZE delivery campaign aimed primarily at U.S. financial services and insurance organizations. The campaign used an inline link to deliver a MAZE executable payload.
Mandiant observed a November 6–7, 2019 campaign targeting Germany with German-language tax/refund and invoice lures delivered through macro-enabled documents. The campaign used malicious domains registered with the address gladkoff1991@yandex.ru.
Mandiant said it was aware of more than 100 alleged MAZE victims reported by media outlets and on the MAZE website since November 2019. The victims spanned nearly every region and many sectors, with a concentration in North America.
Since November 2019, Mandiant assessed that MAZE operations combined targeted ransomware deployment with public exposure of stolen victim data through a dedicated leak site. The same period also marked the use of an affiliate model involving multiple distinct actors and roles.
Mandiant reported that malicious actors had been actively deploying MAZE ransomware since at least May 2019. Early distribution relied on spam emails and exploit kits before later shifting toward post-compromise deployment.
Mandiant documented that at least one MAZE-associated actor attempted lateral movement using EternalBlue during early and late 2019, though it found no evidence the attempts succeeded. This reflects one of the intrusion techniques observed in MAZE operations that year.
SentinelLabs described a MAZE affiliate intrusion against a U.S. company that began on July 4, in which attackers likely brute-forced RDP access, deployed a signed Cobalt Strike stager disguised as netplwiz.exe, and used tailored persistence including SolarWinds Orion DLL hijacking. The defenders detected and mitigated the operation before ransomware was deployed, and the report disclosed infrastructure and techniques including ngrok tunneling, HTA payloads, and sc.exe-based lateral movement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
docs.microsoft.com
Open sourcelabs.sentinelone.com
Open sourcelabs.sentinelone.com
Open sourcesentinelone.com
Open sourcefireeye.com
Open sourceblog.malwarebytes.com
Open sourcefidelissecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.