logo

Using Vectra to Detect and Stop Maze Ransomware by Vectra AI Security Research team

ID: 6622c31c-c06b-5a77-9b8e-ec66f4f86007

STIX ID: report--6622c31c-c06b-5a77-9b8e-ec66f4f86007

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2023-09-29

Date Updated: 2026-05-01

...
...

This report describes the Maze ransomware family (aka ChaCha), its pioneering double-extortion model (encrypting data and exfiltrating it for blackmail), common attack progression (initial compromise, reconnaissance/privilege escalation, lateral movement, exfiltration, and ransomware detonation), observed tooling (Cobalt Strike, Mimikatz, PsExec, BloodHound), and how Vectra AI’s behavior-based detections identify precursor behaviors and active infections, illustrated by a post-incident case where reconnaissance and data exfiltration were detected prior to encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.