diff --git a/clusters/ransomware.json b/clusters/ransomware.json index 482c2e7..460f3e8 100644 --- a/clusters/ransomware.json +++ b/clusters/ransomware.json @@ -13559,7 +13559,20 @@ }, "uuid": "6cea5546-1e2c-333a-4faf-033d461360b5", "value": "Desync" + }, + { + "description": "Maze Ransomware encrypts files and makes them inaccessible while adding a custom extension containing part of the ID of the victim. The ransom note is placed inside a text file and an htm file. There are a few different extensions appended to files which are randomly generated.", + "meta": { + "encryption": "ChaCha20 and RSA", + "refs": [ + "https://malpedia.caad.fkie.fraunhofer.de/details/win.maze", + "https://www.bleepingcomputer.com/news/security/maze-ransomware-now-delivered-by-spelevo-exploit-kit/", + "https://www.proofpoint.com/us/threat-insight/post/ta2101-plays-government-imposter-distribute-malware-german-italian-and-us" + ] + }, + "uuid": "7cea8846-1f3d-331a-3ebf-055d452351b6", + "value": "Maze" } ], - "version": 71 + "version": 72 }