• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
TechEngage

TechEngage®

Hands-on reviews, research-backed buying guides and technology news.

  • News
  • AI
  • Mobile
  • Apps
  • Reviews
  • More
    • Security
    • Internet & Social
    • Computing
    • Gadgets
    • Gaming
    • Car Tech
    • Business
    • Science & Health
TechEngage » Security & Privacy

The rise of the first cyber extortion cartel

Avatar for David Balaban David Balaban Follow David Balaban on X Published: Sep 11, 2020 · 6:21 PM ET Updated: Jan 2, 2021 · 1:00 PM ET

A person coding on his computer
Shares5FacebookTweetPinLinkedInPrint

Although different ransomware gangs operate in the same niche of cybercrime, they are rivals that don’t share their tactics, techniques, and procedures with like-minded bad actors. Conspiracy is a way to maintain a “competitive advantage” that involves infection vectors, cryptographic implementation, operations security (OPSEC), and peculiarities of the Command & Control (C2) infrastructure. These groups are much like lone wolves that hunt down prey on their own and hate it when other predators enter their territory.

This unspoken principle has recently changed, though. Several independent extortion campaigns initiated a merger to create a cartel-type entity that uses common tools and exchanges knowledge about ransomware deployment schemes.

Maze ransomware breaks new ground

A once-marginal ransomware lineage called Maze has been the driving force of the cyber blackmail evolution since November 2019. Back then, its authors showed their ambitions by pioneering in the implementation of a dual extortion model. In addition to encrypting an organization’s data, they inflict an extra sucker punch by stealing it.

Maze operators then threaten to spill these corporate secrets into the wild to pressure the victim into paying the ransom. To take this disgusting ultimatum tactic further, they have set up a site named “Maze News,” where they publish files belonging to non-paying businesses. More than a dozen ransomware groups have since followed suit.

In early June 2020, the gang made another unprecedented move. It teamed up with a previously unrelated ransomware syndicate known as LockBit. Security analysts discovered this plot when Maze’s leak site was updated with a batch of files pilfered from an international architectural company. The inconsistency was that this information had been reportedly obtained in a raid by LockBit rather than Maze.

LockBit debuted last year as a Ransomware-as-a-Service (RaaS) platform actively promoted in the Russian cybercrime underground. It homes in on enterprise networks. Having hit an organization through phishing or an unsecured remote desktop protocol (RDP) connection, its distributors use post-exploitation tools to exfiltrate as much data as they can find. This is what happened to the company whose files ended up on the Maze “public shaming” site.

To dot the i’s and cross the t’s in this story, researchers at the Bleeping Computer security resource tried to get in touch with Maze operators. On a side note, these white hats have a long track record of communicating with ransomware authors on different occasions. This time, they asked whether or not Maze and LockBit had established some kind of a partnership.

Believe it or not, the felons replied. They confirmed that they were cooperating with the LockBit crew. The purpose of forming this wicked tandem was to use a single data leak platform and share expertise regarding different stages of the extortion workflow.

Maze actors emphasized that they treated the joining group as partners rather than competitors. They also announced that one more cybercriminal ring would enhance the “union” shortly. They refused to provide commentary about the cartel’s revenue-sharing principles, though.

Another gang jumps on the hype train

A few days after the collaboration with LockBit was confirmed, the Maze group welcomed a new accomplice – a ransomware family called Ragnar Locker. In contrast to LockBit that never had a leak website of its own, the newbie had created such a resource long before the merger. It’s, therefore, unclear what motivated the felons to start working under the same umbrella. The main theory is that the perpetrators would be getting a cut from the combined illicit profits.

On June 9, a portion of information stolen from a US-based marketing agency called Brunner was uploaded to Maze’s site for data dumps. This attack had been previously attributed to Ragnar Locker, which provided extra proof that the evil alliance was real.

The inner workings of the cartel

When the activity of the newly formed extortion trio was in full swing, the story took an unexpected turn. In late August, the above-mentioned Bleeping Computer security outlet was contacted by representatives of a ransomware group called SunCrypt, which was first spotted in October 2019.

In their message, the malefactors claimed to have recently become a part of the Maze coalition. Surprisingly, these black hats didn’t mind revealing some intricate details of the dodgy teamwork. According to SunCrypt actors, the primary reason why Maze proprietors have been inviting other gangs to collaborate is that they could no longer handle all the operations on their own.

This statement contradicts the earlier narrative about simply sharing intelligence and offensive tools for mutual benefit. It turned out that the perpetrators took too much on and needed outside assistance to keep their nasty business up and running.

The felons also mentioned that Maze operators had gained a foothold in an undisclosed number of enterprise networks but lacked time and resources to execute the extortion onslaughts. Therefore, they decided to outsource the actual attack function to the associates in exchange for a cut of the future ransom earnings.

Around the same time, security enthusiasts came across a sample of the SunCrypt ransomware and analyzed it extensively. This scrutiny revealed a clue about the collaboration between SunCrypt and Maze, confirming the statements previously made by the former gang.

According to these findings, the deleterious program is executed in a host network through a surreptitious PowerShell script. When running, its underlying DLL component encrypts all potentially valuable data found on the networked computers. It also concatenates each filename with a different hexadecimal hash and drops ransom notes into all folders containing scrambled data.

Whereas this is a classic tactic used by the vast majority of ransom Trojans, there is something that makes SunCrypt stand out from the crowd. Once deployed, it establishes a connection with a particular IP address (91.218.114.31) to submit the details about the victim to its operators.

The involvement of this IP in the SunCrypt attack chain speaks volumes about its ties with the Maze campaign. Here is why: the Maze group uses public IP addresses, including this one, to host its data leak site and C2 infrastructure. Despite this ostensibly lame OPSEC, none of the malicious resources has been knocked offline by law enforcement.

It looks like the extortionists behind Maze have masterminded a way to make the web backbone of their operation fly below the radar of regulatory authorities. Now, they appear to be sharing this know-how with partners operating under the same hood.

By the way, in another round of correspondence with security researchers, Maze denied being in cahoots with SunCrypt and stated that the less successful gang was simply trying to feign affiliation with the notorious cartel to instill fear in victims. However, the use of a common IP address to mount new attacks and amass information about infected businesses is at odds with this refutation.

Summary

The first-ever ransomware alliance formed by the Maze group is another milestone in the evolution of cybercrime. The operators of other impactful strains such as Sodinokibi, Ryuk, and Clop will likely follow in the footsteps of their agile counterparts, as they did with the data leak strategy introduced almost a year ago.

By sharing skills, technologies, and centralized platforms for data dumps, extortionists can boost the success rate of their attacks. This, in turn, will probably lead to an increase in the average size of the ransom down the road. Under the circumstances, proactive defenses, security awareness training programs, and data backups are more important for organizations than ever before.


Related reading

  • Cybersecurity Awareness Tips for Employees
  • How to Protect Your Digital Identity and Social Media Accounts
  • State-Sponsored Cyber Warfare Units and the Global Threat Landscape
  • Best Private Search Engines: 10 Secure Alternatives to Google

Filed Under: Security & Privacy Tagged With: Cybersecurity

Related Stories

  • How Does A Vpn Protect User Privacy And Anonymity?

    How does a VPN protect user privacy and anonymity?

    Security & PrivacyJul 15, 2023

  • What Is Cloud Security

    What is Cloud Security

    Security & PrivacyJul 6, 2023

  • How To Secure Data Transfer In 2026: Tls, Sftp, Encryption And Passkeys

    How to Secure Data Transfer in 2026: TLS, SFTP, Encryption and Passkeys

    Security & PrivacyJul 5, 2023

Stay on top of technology

Get TechEngage reviews, buying guides and news in your feed.

Follow on Google News
Shares5FacebookTweetPinLinkedInPrint
Avatar for David Balaban

David Balaban

Contributor

David Balaban is a computer security researcher with more than 17 years of experience in malware analysis and antivirus evaluation. He runs the MacSecurity.net and Privacy-PC.com projects and writes on malware, social engineering, threat intelligence, online privacy, and ransomware. He contributed a guest article on security to TechEngage.

Joined TechEngage August 2020First article on TechEngage September 2020

Reader Interactions

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Google News

Get TechEngage in your feed

Reviews, news, and buying guides as they publish.

Follow on Google News

Recent Stories

  • Ai Markets Feat |
    AIThree CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.Sep 21, 2026
  • Iphone 18 Pro Availability Sept 18 |
    Tech News & AnalysisiPhone 18 Pro and Pro Max Available Today in 65+ CountriesSep 18, 2026
  • Best Portable Monitors 2026 |
    Reviews & Buying GuidesBest Portable Monitors in 2026: 8 Picks for Travel, Work, and PlaySep 18, 2026
  • Samsung One Ui 9 Android 17 Rollout |
    Tech News & AnalysisSamsung Starts One UI 9 (Android 17) Rollout on Galaxy S26 SeriesSep 17, 2026
  • Best Wireless Mice 2026 |
    Reviews & Buying GuidesBest Wireless Mice in 2026: 8 Picks for Work, Travel, and PlaySep 17, 2026

More in Security & Privacy

  • C Users Mumo Downloads Privecstasy Cxlqhmqy3My Un Jpeg |
    Security & PrivacyHow does a VPN protect user privacy and anonymity?Jul 15, 2023
  • Cloud Security Pexels Christina Morillo Jpg |
    Security & PrivacyWhat is Cloud SecurityJul 6, 2023
  • Secure Data Transfer Jpg |
    Security & PrivacyHow to Secure Data Transfer in 2026: TLS, SFTP, Encryption and PasskeysJul 5, 2023
  • Photo 2023 05 23 19 03 36 Jpg |
    Security & Privacy5 Internet Security Suites to Get For Fortifying Your Internet SecurityMay 24, 2023
More Security & Privacy stories →

Footer

Discover

  • About TechEngage
  • Company News & Updates
  • Our Team
  • Advertise
  • Send us a tip
  • Startup Submissions
  • TechEngage Brand Kit
  • Contact us
  • Tools

Legal pages

  • Editorial Standards
  • Reviews Policy
  • Our Ethics
  • Corrections Policy
  • Affiliate Disclosure
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • GDPR Compliance
  • Copyright & DMCA

Must reads

  • Best Mechanical Keyboards Under $100
  • Best USB-C Hubs
  • Best Portable SSDs
  • Best Gaming Graphics Cards (GPUs)
  • Best Long-Range Outdoor WiFi Extenders
  • Best Wireless CarPlay Adapters
  • Best Slack Alternatives
  • Best Long-Range Walkie-Talkies

About TechEngage

TechEngage® is an independent technology publication covering tech news, reviews and buying guides since 2003.

Founded
2003
Publisher
TechAbout LLC
ISSN
2690-3776
Google NewsRSS feed

© 2026 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

Contact [email protected] · WhatsApp +1-307-381-8801