Uptime Hamster: 35d 23h 54mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza maze

maze

2 incidentes 0 paises 1 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: ChaCha, Moonlight_Maze, está vinculado a actividades de ciberataques, Criminal, Cyfirma, quien ha afirmado un vínculo con APT29, APT DEATHSTALKER
Ver en IntelTracker → APTTrail →
Maze ransomware emerged in May 2019, initially identified as 'ChaCha ransomware,' and quickly distinguished itself by pioneering the double extortion technique. This method involved not only encrypting victims' data but also exfiltrating sensitive information and threatening its public release if a ransom was not paid. Operating with an affiliate-based model, Maze operators also maintained a dedicated public-facing website, 'Maze News,' to list victims and publish stolen data, significantly increasing pressure on organizations. While the group claimed to officially cease operations in November 2020, its tactics and a potential rebranding have been observed in subsequent ransomware variants like Egregor and Sekhmet. The group's primary motivation was financial gain through extortion, and it is assessed with high confidence to be of Russian origin, indicated by its malware avoiding systems configured with Russian or former Soviet Union languages.

Aliases del actor

ChaChaMoonlight_Mazeestá vinculado a actividades de ciberataquesCriminalCyfirmaquien ha afirmado un vínculo con APT29APT DEATHSTALKER

Actores similares

apt-deathstalkeractor · 1apt-desertfalconactor · 1apt-stealthfalconactor · 1apt-c-01actor · 2apt-c-27actor · 2apt-45actor · 2apt-c-37actor · 1apt-c-23actor · 1hellsing-aptactor · 1apt-c-44actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: maze
DLS / onionofflinexfr3txoorcyy7tikjgj5dk3rvo3vsrpyaxnclyohkbfp3h277ap4tiad.onionCTI.FYI
Webunknownwww.secureworks.comOSINT
DLS / leak siteunknowncloud.google.comOSINT
DLS / leak siteunknownwww.crowdstrike.comOSINT
Webunknownwww.cert.ssi.gouv.frOSINT
DLS / leak siteunknownwww.crowdstrike.comOSINT
DLS / leak siteunknowncloud.google.comOSINT
Malware asociado
WannaCry, Qbot, Remcos RAT, Ursnif, Remcos RAT, CHOPSTICK
Tecnicas MITRE
T1133, T1583, T1560, T1105, T1588, T1003
CVEs relacionadas
CVE-2020-0787
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (OSINT)

United Arab EmiratesArgentinaAustraliaBrazilCanadaChinaGermanyFranceUnited KingdomHong Kong

Sectores atacados

Software (1)

Sectores objetivo (OSINT)

Construction of BuildingsOther Information ServicesCredit UnionsSoftware PublishersEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com