ATT&CKReferencesFireEye Maze May 2020

FireEye Maze May 2020

Kennelly, J., Goody, K., Shilko, J. (2020, May 7). Navigating the MAZE: Tactics, Techniques and Procedures Associated With MAZE Ransomware Incidents. Retrieved May 18, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareMaze

The Maze encryption process has used batch scripts with various commands.

T1486
Data Encrypted for Impact
MalwareMaze

Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files.

T1572
Protocol Tunneling
Toolngrok

ngrok can tunnel RDP and other services securely over internet connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.