logo

Ransomware Maze

ID: b0b784d9-9550-580d-aa17-6a5aa324671f

STIX ID: report--b0b784d9-9550-580d-aa17-6a5aa324671f

Feed Name: McAfee Labs Blog

Threat Score
78/100

Date Published: 2020-03-26

Date Updated: 2026-04-28

Author: Alexandre Mundo

...
...

This McAfee technical analysis documents the Maze ransomware (aka ChaCha), describing its goals of encrypting files and extorting victims by threatening data publication, its propagation methods (exploit kits, malicious Office macros, weak RDP), sophisticated anti-analysis/anti-debugging techniques, ChaCha+RSA encryption process, runtime behaviors (mutex, language checks, shadow-copy deletion), associated IOCs (multiple Russian-hosted IPs, mazedecrypt.top, and a YARA rule), and recommended mitigations such as isolated backups, updated AV/patching, disabling unnecessary RDP and Office macros.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.