Uptime Hamster: 10d 10h 13mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza maze

maze

2 incidentes 0 paises 1 sectores ransomware RU Ultimo: 2026-06-29
Aliases: ChaCha, APT DEATHSTALKER, Criminal, Cyfirma, quien ha afirmado un vínculo con APT29, Moonlight_Maze, está vinculado a actividades de ciberataques
Ver en IntelTracker → APTTrail →
Maze ransomware emerged in May 2019, initially identified as 'ChaCha ransomware,' and quickly distinguished itself by pioneering the double extortion technique. This method involved not only encrypting victims' data but also exfiltrating sensitive information and threatening its public release if a ransom was not paid. Operating with an affiliate-based model, Maze operators also maintained a dedicated public-facing website, 'Maze News,' to list victims and publish stolen data, significantly increasing pressure on organizations. While the group claimed to officially cease operations in November 2020, its tactics and a potential rebranding have been observed in subsequent ransomware variants like Egregor and Sekhmet. The group's primary motivation was financial gain through extortion, and it is assessed with high confidence to be of Russian origin, indicated by its malware avoiding systems configured with Russian or former Soviet Union languages.

Aliases del actor

ChaChaAPT DEATHSTALKERCriminalCyfirmaquien ha afirmado un vínculo con APT29Moonlight_Mazeestá vinculado a actividades de ciberataques

Actores similares

apt-deathstalkeractor · 1apt-desertfalconactor · 1apt-stealthfalconactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: maze
Malware asociado
WannaCry, Qbot, Remcos RAT, Ursnif, Remcos RAT, CHOPSTICK
Tecnicas MITRE
T1133, T1583, T1560, T1105, T1588, T1003
CVEs relacionadas
CVE-2020-0787
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaBrazilCanadaChinaGermanyFranceUnited KingdomHong Kong

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesCredit UnionsSoftware PublishersEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com