Maze Ransomware

3794386206?profile=RESIZE_710xFBI Flash Bulletin / TLP GREEN

Unknown cyber actors have targeted multiple US and international businesses with Maze ransomware since early 2019.  Maze encrypts files on an infected computer’s file system and associated network file shares.  Once the victim has been compromised, but prior to the encryption event, the actors exfiltrate data.  After the encryption event, the actors demand a victimspecific ransom amount paid in Bitcoin (BTC) in order to obtain the decryption key.  An international Maze campaign targeted the healthcare sector, while its deployment in the US has been more varied.

Link to full report: flash_maze_ransomware.pdf

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!