Maze

S0449

Malware.View on attack.mitre.org

About this malware

Maze ransomware, previously known as "ChaCha", was discovered in May 2019. In addition to encrypting files on victim machines for impact, Maze operators conduct information stealing campaigns prior to encryption and post the information online to extort affected companies.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1027
Obfuscated Files or Information

Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis.

T1027.016
Junk Code Insertion

Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process.

T1036.004
Masquerade Task or Service

Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware.

T1047
Windows Management Instrumentation

Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network.

T1049
System Network Connections Discovery

Maze has used the "WNetOpenEnumW", "WNetEnumResourceW”, “WNetCloseEnum” and “WNetAddConnection2W” functions to enumerate the network resources on the infected machine.

T1053.005
Scheduled Task

Maze has created scheduled tasks using name variants such as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update", to launch Maze at a specific time.

T1055.001
Dynamic-link Library Injection

Maze has injected the malware DLL into a target process.

T1057
Process Discovery

Maze has gathered all of the running system processes.

T1059.003
Windows Command Shell

The Maze encryption process has used batch scripts with various commands.

T1070
Indicator Removal

Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection.

T1071.001
Web Protocols

Maze has communicated to hard-coded IP addresses via HTTP.

T1082
System Information Discovery

Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function.

T1106
Native API

Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others.

T1218.007
Msiexec

Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using msiexec.

T1486
Data Encrypted for Impact

Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files.

View all 23 procedure examples

Groups that use it2

Campaigns0

None recorded.

References3

  1. FireEye Maze May 2020 Open source
    Kennelly, J., Goody, K., Shilko, J. (2020, May 7). Navigating the MAZE: Tactics, Techniques and Procedures Associated With MAZE Ransomware Incidents. Retrieved May 18, 2020.
  2. McAfee Maze March 2020 Open source
    Mundo, A. (2020, March 26). Ransomware Maze. Retrieved May 18, 2020.
  3. Sophos Maze VM September 2020 Open source
    Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.