Maze emerged as one of the most influential ransomware operations targeting businesses, corporations, and municipal organizations, combining file encryption with data theft and public leak threats to force victims into paying. The group first spread through exploit kits and malicious spam, then shifted to more targeted intrusions using spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and attacks against weak RDP credentials.
Researchers described Maze as a C/C++ Windows PE malware with obfuscation, anti-analysis features, and a layered encryption scheme that paired ChaCha with RSA-2048. The operation also expanded its influence by forming a ransomware cartel with LockBit and RagnarLocker, sharing leak infrastructure and tradecraft in a model that helped normalize double-extortion tactics across the broader ransomware ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In June 2020, the criminals behind Maze teamed up with LockBit and RagnarLocker to form a ransomware cartel. Stolen data from all three groups was published on the blog maintained by Maze operators, and the groups shared leak infrastructure and tradecraft.
As of mid-December 2019, Maze operators had publicly named 11 victims that allegedly refused to pay and posted proof-of-compromise material. The disclosures included stolen documents or databases, exfiltrated data volumes, and host details to pressure victims into paying.
The history of Maze ransomware began in the first half of 2019. Early versions lacked distinct Maze branding, used the ransom note title "0010 System Failure 0010," and were initially referred to by researchers as ChaCha ransomware.
Maze was initially spread through exploit kits and spam campaigns, but operators later moved to targeted attacks against corporations and municipal organizations. These intrusions used spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and weak RDP credentials.
Later Maze versions adopted the Maze name and used a dedicated victim website. The group paired encryption with threats to publicly leak stolen confidential data, helping establish the leak-and-extort model.
On 29 May 2019, newer ransomware variants explicitly identified themselves as Maze rather than only being tracked under the earlier ChaCha naming. This marked the transition from the early ChaCha-branded phase to the Maze name.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcesecurelist.com
Open sourcembsd.jp
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.