Security researchers reported that Maze ransomware was delivered through the Spelevo exploit kit, which abused CVE-2018-15982, a critical Adobe Flash Player flaw, to execute code and install the payload. Once launched, Maze encrypted files with RSA and ChaCha20, dropped the DECRYPT-FILES.txt ransom note, and directed victims to both Tor and clear-web payment portals that offered live chat and limited test decryption. Researchers also linked Maze to earlier delivery through the Fallout exploit kit, showing that the operators used multiple infection channels to spread the malware.
Separate incident-response findings showed Maze operators evolving beyond simple encryption into targeted intrusions that paired ransomware with data theft and extortion. Cisco Talos observed attackers using Cobalt Strike after initial access, moving laterally for at least a week, logging in interactively over RDP, executing remote PowerShell through WMIC, compressing stolen data with 7-Zip, and exfiltrating it via PowerShell to a remote FTP server before deploying the ransomware. The activity reflected a broader shift in ransomware operations toward stealing sensitive files first and then threatening public release to increase pressure on victims.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft said the campaign began early in the morning on Wednesday, November 14, targeting public sector institutions, NGOs, think tanks, research centers, and some education and private-sector organizations. The phishing emails mimicked OneDrive sharing notifications and led victims to a compromised website that ultimately delivered a DLL backdoor and Cobalt Strike.
Cisco Talos Incident Response investigated multiple targeted ransomware incidents in which the same adversary used Cobalt Strike, lateral movement, 7-Zip compression, PowerShell-based FTP exfiltration, and then deployed Maze ransomware. Talos assessed with high confidence that at least two incidents were linked to the same adversary and highlighted the use of extortion threats tied to public release of stolen data.
Security researchers observed a new campaign in which the Spelevo exploit kit exploited CVE-2018-15982 in Adobe Flash Player to download and install Maze ransomware. Researcher nao_sec first spotted the activity, and GrujaRS analyzed it shortly afterward.
Maze ransomware was initially found in May, according to the report, and was described as a variant of ChaCha ransomware. Researchers also linked it to earlier distribution through the Fallout exploit kit.
Microsoft published its analysis of the phishing campaign, describing the infection chain, notifying thousands of recipients across hundreds of targeted organizations, and stating that Office 365 ATP and Windows Defender ATP detected the activity. While third-party researchers attributed the operation to APT29/Cozy Bear, Microsoft said it lacked sufficient evidence to make that attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcebleepingcomputer.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.