Using Vectra to Detect and Stop Maze Ransomware by Vectra AI Security Research team
ID: 6622c31c-c06b-5a77-9b8e-ec66f4f86007
STIX ID: report--6622c31c-c06b-5a77-9b8e-ec66f4f86007
Feed Name: Vectra AI Blog
This report describes the Maze ransomware family (aka ChaCha), its pioneering double-extortion model (encrypting data and exfiltrating it for blackmail), common attack progression (initial compromise, reconnaissance/privilege escalation, lateral movement, exfiltration, and ransomware detonation), observed tooling (Cobalt Strike, Mimikatz, PsExec, BloodHound), and how Vectra AI’s behavior-based detections identify precursor behaviors and active infections, illustrated by a post-incident case where reconnaissance and data exfiltration were detected prior to encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
