Threat Brief: Maze Ransomware
Unit 42 issued a threat brief on Maze ransomware, noting an uptick across industries and exploitation of Pulse VPN and IE flaws for initial access.
Palo Alto Networks detected an uptick in Maze ransomware samples across finance, healthcare, government, and other sectors. Maze, a variant of ChaCha ransomware first seen in May 2019, is distributed via weaponized Word/Excel attachments and the Spelevo exploit kit leveraging CVE-2018-15982 and CVE-2018-4878, and has used CVE-2019-11510 (Pulse VPN) and CVE-2018-8174 (Internet Explorer). Operators establish a foothold, escalate privileges, move laterally, and exfiltrate files before encryption for extortion leverage.
- Maze distributed via weaponized Office attachments and Spelevo exploit kit
- Exploited CVE-2019-11510 (Pulse VPN) and CVE-2018-8174 (IE)
- Pre-encryption data exfiltration used for public exposure coercion
- Affected industries span finance, healthcare, government, and utilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-15982 | Use-After-Free in Adobe Flash Player Allows Arbitrary Code Execution CVE-2018-15982 is a use-after-free flaw (CWE-416) in Adobe Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier, in which Flash frees memory that is subsequently reused, corrupting process memory. It is triggered when Flash processes crafted Flash content, most notably embedded in Microsoft Office documents, requiring a user to open or view the malicious content (CVSS attack vector is local with user interaction required). Successful exploitation gives the attacker arbitrary code execution with the privileges of the user viewing the content. Affected users include anyone running the listed Flash Player versions, including the Flash Player Installer and the Adobe-supplied Flash plugin shipped with Red Hat Enterprise Linux Desktop, Server and Workstation. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15) with known ransomware use, a public exploit is available on Exploit-DB, and EPSS assigns a top-percentile 89.1% probability of exploitation within 30 days. Do: Flash Player is end-of-life: per CISA's required action, remove or disconnect Flash wherever it is still in use; if Flash must remain, update beyond the affected 31.0.0.153/31.0.0.108 builds and update the flash-plugin package on Red Hat Enterprise Linux. Mitigate the known delivery vector by blocking or disabling embedded Flash (SWF) content in Microsoft Office documents and mail clients, and hunt for suspicious documents with embedded Flash given the known in-the-wild and ransomware use. | 7.8 | 89% | KEV ransomware PoC |
| mass≈100M+ endpoints historically (Flash was preinstalled/bundled across most Windows desktops and shipped with Chrome and RHEL in 2018); only residual legacy… | |
| CVE-2018-4878 | Use-After-Free RCE in Adobe Flash Player before 28.0.0.161 CVE-2018-4878 is a use-after-free (CWE-416) in Adobe Flash Player before 28.0.0.161, caused by a dangling pointer in the Primetime SDK's media-player handling of listener objects. An attacker triggers it by persuading a user to open attacker-controlled Flash content — typically a malicious SWF delivered via email, Office documents, or malvertising/exploit kits — because the CVSS vector (AV:L, UI:R) requires local user interaction. Successful exploitation yields arbitrary code execution with the privileges of the user running Flash. Anyone running a vulnerable Flash Player was exposed, including Red Hat Enterprise Linux Desktop/Server/Workstation users running Red Hat's packaged Flash plugin. The flaw was exploited as a zero-day in January–February 2018 (documented by McAfee and distributed alongside the Fallout exploit kit), and it remains in CISA's KEV with known ransomware use. Do: Upgrade Adobe Flash Player to 28.0.0.161 or later, including Red Hat's flash-plugin package on RHEL Desktop/Server/Workstation. Because Flash is now end-of-life, CISA's required KEV action is to remove or disconnect Flash entirely where still in use — audit browsers, Office configurations, and legacy RHEL hosts for residual Flash installs, and block SWF content delivered via email and the web. Given confirmed in-the-wild exploitation, known ransomware use, and 89.5% EPSS, prioritize this in remediation tracking. | 7.8 | 90% | KEV ransomware PoC ×2 |
| mass≈ hundreds of millions of desktop installs at time of disclosure; residual unmigrated installs now unknown (Flash is end-of-life) | |
| CVE-2018-8174 | Out-of-Bounds Write RCE in Microsoft Windows VBScript Engine CVE-2018-8174 is an out-of-bounds write (CWE-787) in the Microsoft Windows VBScript engine, caused by the way it handles objects in memory. An attacker triggers it by convincing a user to visit a specially crafted website or open crafted content that invokes the VBScript engine (for example via Internet Explorer or a document preview), requiring user interaction. Successful exploitation yields remote code execution with the privileges of the logged-on user, enabling program installation, data theft and account takeover. All listed Windows client and server releases are affected: Windows 7, 8.1, RT 8.1, Windows 10 (1607-1803), and Windows Server 2008/2008 R2, 2012/2012 R2, 2016. Exploitation is in the wild: the flaw was fixed in the May 2018 Patch Tuesday, is listed in CISA KEV with known ransomware use, and public PoCs (0patch, ExploitDB 44741) and exploit kit usage have been documented; EPSS puts its 30-day exploitation probability at 88.5%. Do: Apply Microsoft's May 2018 security updates (and any later cumulative or Extended Security Updates) to every listed Windows client and server release, as required by the CISA KEV listing, prioritizing internet-reachable and user-facing systems given known ransomware use. Upgrade out-of-support platforms (Windows 7/8.1/RT 8.1, Server 2008/2008 R2, 2012/2012 R2) to supported builds or ensure ESU coverage. As interim mitigation, block VBScript execution in Internet Explorer web zones using Microsoft's documented Group Policy/registry settings, and hunt for prior exploitation on legacy systems. | 7.5 | 88% | KEV ransomware PoC ×2 |
| masshundreds of millions of Windows PCs and servers (affected desktop releases dominated the ~1B+ device Windows install base at disclosure) | |
| CVE-2019-11510 | Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known. Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users) |
Full article1,425 words · extracted from unit42.paloaltonetworks.com · click to collapse
Executive Summary
Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the Unit 42 Playbook Viewer.
Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized Word or Excel attachments. However, it has also been distributed via exploit kits such as the Spelevo Exploit Kit, which has been used with Flash Player vulnerabilities CVE-2018-15982 and CVE-2018-4878. Maze ransomware has also utilized exploits CVE-2019-11510 (Pulse VPN), as well as CVE-2018-8174 (Internet Explorer) to get into a network. The malware first establishes a foothold within the environment. It then obtains elevated privileges, conducts lateral movement, and begins file encryption across all drives. However, before encrypting the data, these operators may exfiltrate the files to be used for further coercion, including public exposure. Without the proper protections in place, a Maze ransomware infection will cripple normal business operations, and sensitive information will be compromised, resulting in a monetary loss.
Maze has not only been observed globally, but also affecting varying industries, which include: finance, technology, telecommunications, healthcare, government, construction, hospitality, media and communications, utilities and energy, pharma and life sciences, education, insurance, wholesale, and legal. On March 26, 2020, McAfee published a report providing a detailed overview of the Maze ransomware.
Palo Alto Networks Cortex XDR contains an Anti-Ransomware Protection module, which targets encryption-based activities associated with ransomware. Customers can also review activity associated with this Threat Brief via AutoFocus.
Impact Assessment
Several adversarial techniques were observed in this activity.
The following measures are suggested within Palo Alto Networks products and services for Maze ransomware:
| Tactic | Technique (Mitre ATT&CK ID) | Product/Service | Course of Action |
| Initial Access | External Remote Services(T1133) | NGFW | Configure Interfaces and Zone segmentation |
| Threat Prevention† | Deploy Vulnerability Protection Profile for all low and high severity threats with block action | ||
| Cortex XDR | Configure Host Firewall Profile | ||
| Initial Access | Spear-Phishing Attachment (T1193) | NGFW | Configure a File Blocking Profile |
| Threat Prevention† | Enable Anti-Virus profile with reset-both action | ||
| WildFire | Forward files for WildFire Analysis | ||
| Cortex XDR | Configure Malware Security Profile | ||
| Initial Access | Drive-by Compromise(T1189) | NGFW | Block all unknown and unauthorized applications |
| Threat Prevention† | Deploy Vulnerability Protection Profile for all low and high severity threats with block action | ||
| DNS Security† | Enable DNS Security in Anti-Spyware profile | ||
| URL Filtering† | Control web access based on URL Category | ||
| WildFire | Forward Files for WildFire Analysis | ||
| Initial Access | Trusted Relationship (T1199) | NGFW | Configure Interfaces and Zones segmentation |
| Initial AccessPrivilege EscalationPersistenceDefense Evasion | Valid Accounts (T1078) | NGFW | Configure Multi-Factor Authentication |
| Threat Prevention† | Enable Credential Phishing protection | ||
| Cortex XSOAR | Deploy Cortex XSOAR Playbook - Access Investigation | ||
| Execution Defense Evasion | Scripting(T1064) | WildFire | Forward Files for WildFire Analysis |
| Cortex XDR | Enable Anti-Exploit and Anti-Malware Protection | ||
| Execution | Powershell (T1086) | Cortex XDR | Enable Anti-Exploit and Anti-Malware Protection |
| Execution | Command-Line Interface (T1059) | Cortex XDR | Enable Anti-Exploit and Anti-Malware Protection |
| Execution | Service Execution (T1035) | Cortex XDR | Configure Behavioral Threat Protection under the Malware Security Profile |
| Persistence | Modify Existing Service (T1031) | Cortex XDR | Configure Behavioral Threat Protection under the Malware Security Profile |
| Persistence | Registry Run Keys / Startup Folder (T1060) | Cortex XDR | Configure Behavioral Threat Protection under the Malware Security Profile |
| Persistence | New Service (T1050) | Cortex XDR | Configure Behavioral Threat Protection under the Malware Security Profile |
| Privilege Escalation | Exploitation for Privilege Escalation (T1068) | Cortex XDR | Enable Anti-Exploit and Anti-Malware Protection |
| Defense Evasion | NTFS File Attributes (T1096) | NGFW | Block all unknown and unauthorized applications |
| WildFire | Forward files for WildFire Analysis | ||
| Cortex XDR | Configure Behavioral Threat Protection under the Malware Security Profile | ||
| Defense Evasion | Obfuscated Files or Information(T1027) | WildFire | Forward files for WildFire Analysis |
| Cortex XDR | Enable Anti-Exploit and Anti-Malware Protection | ||
| Defense Evasion | Disabling Security Tools (T1089) | Cortex XDR | Configure Behavioral Threat Protection under the Malware Security Profile |
| Credential Access | Brute Force(T1110) | NGFW | Create a rule to modify the default action for all signatures in the brute force category to block-ip address action |
| Credential Access | Credential Dumping (T1003) | Cortex XDR | Cortex XDR monitors for behavioral events and files associated with credential access and exfiltration |
| Lateral Movement | Remote Desktop Protocol (T1076) | NGFW | Configure Multi Factor Authentication,Create User Group for Limited Access to Allow List Applications,Configure Interfaces and Zones segmentation |
| Cortex XDR | Configure Host Firewall Profile | ||
| Collection | Data from Local System (T1005) | Cortex XDR | Cortex XDR monitors for behavioral events and files associated with collection activities |
| Command and Control | Standard Application Layer Protocol(T1071) | NGFW | Block all unknown and unauthorized applications |
| DNS Security† | Deploy Anti-Spyware profiles with block action | ||
| Cortex XDR | Cortex XDR monitors for behavioral events indicative of command and control activity | ||
| Command and Control | Remote File Copy (T1105) | NGFW | Block all unknown and unauthorized applications |
| WildFire | Forward files for WildFire Analysis | ||
| Cortex XDR | Cortex XDR monitors for behavioral events associated with file creation, staging, and exfiltration | ||
| Command and Control | Standard Cryptographic Protocol (T1032) | NGFW | Block all unknown and unauthorized applications, Enable SSL decryption |
| DNS Security† | Enable DNS Security in Anti-Spyware profile | ||
| WildFire | Forward SSL decrypted files to WildFire | ||
| Discovery | File and Directory Discovery (T1083) | Cortex XDR | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors |
| Discovery | Network Share Discovery (T1135) | Cortex XDR | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors |
| Discovery | Process Discovery (T1057) | Cortex XDR | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors |
| Discovery | Software Discovery (T1518) | Cortex XDR | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors |
| Discovery | System Information Discovery (T1082) | Cortex XDR | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors |
| Exfiltration | Data Encrypted(T1022) | Cortex XDR | Configure Behavioral Threat Protection under the Malware Security Profile |
| Exfiltration | Exfiltration Over Alternative Protocol (T1048) | NGFW | Block all unknown and unauthorized applications. profile |
| DNS Security† | Enable DNS Security in Anti-Spyware | ||
| Exfiltration | Exfiltration Over Command and Control (T1041) | NGFW | Block all unknown and unauthorized applications |
| DNS Security† | Enable DNS Security in the Anti-Spyware profile | ||
| Threat Prevention† | Enable Anti-Spyware Profile with Block Action | ||
| Impact | Data Encrypted for Impact (T1486) | Cortex XSOAR | Deploy Cortex XSOAR Playbook - Ransomware Manual for incident response |
Table 1. Course of Action for Maze Ransomware
† These capabilities are part of the NGFW security subscriptions service
Recently, malicious operators behind the Maze ransomware activities compromised multiple IT service providers. These operators were also able to establish a foothold within another victim’s network through insecure Remote Desktop Protocol and other remote service connections or by brute-forcing the local administrator account. Organizations should be mindful of potential compromises through third-party sources and ensure strong passwords are used for all systems capable of remote access.
It was also reported that Maze operators pay special attention to cloud backups on the compromised network. If the operators were to obtain login credentials, they are then able to download all backup data to an actor controlled server. Organizations should ensure that all cloud backup files are properly stored and protected.
Threat Education
What is Ransomware?
Ransomware is a criminal business model that uses malicious software to hold valuable files and other data for ransom. Victims of ransomware attacks may have their operations degraded or shut down entirely.
For additional details on a What is Ransomware?, visit the Palo Alto Networks Cyberpedia:
https://www.paloaltonetworks.com/cyberpedia/what-is-ransomware
Palo Alto Networks customers can review activity associated with this Threat Brief via AutoFocus using the following tag: Maze, SpelevoEKFlashContainer
Palo Alto Networks Cortex XDR contains an Anti-Ransomware Protection module. This module targets encryption-based activity associated with ransomware. Cortex XDR contains defined behavioral indicators of compromise designed to detect anomalies within your network.
More information on ransomware can be found in the 2021 Unit 42 Ransomware Threat Report.
References
https://download.bitdefender.com/resources/files/News/CaseStudies/study/318/Bitdefender-TRR-Whitepaper-Maze-creat4351-en-EN-GenericUse.pdf
https://www.docdroid.net/dUpPY5s/maze-pdf#page=2
The suggested courses of action in this report are based on the information currently available to Palo Alto Networks and the capabilities within Palo Alto Networks products and services.
Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/threat-brief-maze-ransomware-activities/