diff --git a/clusters/ransomware.json b/clusters/ransomware.json index 90273df..9ad0e0e 100644 --- a/clusters/ransomware.json +++ b/clusters/ransomware.json @@ -13556,7 +13556,20 @@ }, "uuid": "6cea5546-1e2c-333a-4faf-033d461360b5", "value": "Desync" + }, + { + "description": "Maze Ransomware encrypts files and makes them inaccessible while adding a custom extension containing part of the ID of the victim. The ransom note is placed inside a text file and an htm file. There are a few different extensions appended to files which are randomly generated.", + "meta": { + "encryption": "ChaCha20 and RSA", + "refs": [ + "https://malpedia.caad.fkie.fraunhofer.de/details/win.maze", + "https://www.bleepingcomputer.com/news/security/maze-ransomware-now-delivered-by-spelevo-exploit-kit/", + "https://www.proofpoint.com/us/threat-insight/post/ta2101-plays-government-imposter-distribute-malware-german-italian-and-us" + ] + }, + "uuid": "7cea7746-1f2d-321a-3fbf-044d451350b6", + "value": "Maze" } ], - "version": 71 + "version": 72 }