Ransomware Maze
ID: b0b784d9-9550-580d-aa17-6a5aa324671f
STIX ID: report--b0b784d9-9550-580d-aa17-6a5aa324671f
Feed Name: McAfee Labs Blog
This McAfee technical analysis documents the Maze ransomware (aka ChaCha), describing its goals of encrypting files and extorting victims by threatening data publication, its propagation methods (exploit kits, malicious Office macros, weak RDP), sophisticated anti-analysis/anti-debugging techniques, ChaCha+RSA encryption process, runtime behaviors (mutex, language checks, shadow-copy deletion), associated IOCs (multiple Russian-hosted IPs, mazedecrypt.top, and a YARA rule), and recommended mitigations such as isolated backups, updated AV/patching, disabling unnecessary RDP and Office macros.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
