HomeSecurityThe operators of the Maze ransomware are ending their operation!

The operators of the Maze ransomware are shutting down their operation!

The Maze gang is shutting down its operations after becoming one of the most prominent players in the ransomware market. The Maze ransomware began operating in May 2019, but became more active in November of the same year.

The company revolutionized ransomware attacks by introducing a double extortion tactic.

maze

First, they steal your files and then encrypt them

While ransomware operations, for the most part, tend to ignore journalists' emails, that changed in November 2019, when the Maze team contacted BleepingComputer to inform them that they had stolen Allied Universal's data

Maze's team stated that if Allied did not pay the ransom, their data would be released to the public. Ultimately, the ransom was not paid and Maze released the stolen data.

Shortly thereafter, Maze launched a website called “Maze News” which they use to publish data on victims who do not pay and issue “press releases” for journalists who monitor activities .

This double extortion technique was quickly adopted by other major ransomware operations, including REvil, Clop, DoppelPaymer, who launched their own data extortion websites. This double extortion technique has now become a standard tactic used by almost all ransomware groups.

The Maze team continued to evolve the ransomware's functionality by forming a cartel with the Ragnar Locker and LockBit teams to share information and tactics.

During the year and a half it was in operation, Maze was responsible for attacks on very important businesses, including Southwire, City of Pensacola, Canon, LG Electronics, Xerox, and many others.

Maze stopped about six weeks ago

Early last month, BleepingComputer began hearing rumors that the Maze team was preparing to shut down the operation in a similar manner to the GandCrab team in 2019.

The closure was later confirmed after BleepingComputer spoke with an attacker involved in the attack that took place atBarnes and Noble.

The Maze group is in the process of shutting down its operations, having stopped encrypting new victims since September 2020, and is trying to pressure its last victims to pay the ransom.

This week, the Maze team began removing victims it had listed on the data leak website. The cleanup of the data leak indicates that the ransomware will be terminated.

Partners move to Egregor ransomware

BleepingComputer has learned that many Maze collaborators have switched to a new ransomware group called Egregor.

The Egregor group began operating in mid-September and quickly became quite well-known.

The Egregor ransomware is believed to be similar to Maze and Sekhmet, as they use the same “ransom notes”, similar payment website name, and share much of the same code.

This was also confirmed by a hacker who stated that Maze, Sekhmet, and Egregor were the same software.

Unfortunately, this shows that even when a ransomware operation is shut down, it doesn't mean the threat actors are gone. They simply move on to another group/operation.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS