TA2101
Also reported as Maze Team, Storm-0216, UNC2198, TUNNEL SPIDER, TWISTED SPIDER and 4 other names. Linked to Russia by two sources.
Reports per quarter
Techniques seen in the last two years
- T1033 3 reports
- T1219 3 reports
- T1489 3 reports
- T1572 3 reports
- T1016 2 reports
- T1018 2 reports
- T1021.001 2 reports
- T1021.004 2 reports
- T1046 2 reports
- T1049 2 reports
Show all 256 techniques Show fewer
- T1055.002 2 reports
- T1056.001 2 reports
- T1059 2 reports
- T1059.001 2 reports
- T1059.003 2 reports
- T1059.004 2 reports
- T1068 2 reports
- T1070.004 2 reports
- T1071.001 2 reports
- T1071.004 2 reports
- T1078 2 reports
- T1078.004 2 reports
- T1083 2 reports
- T1087 2 reports
- T1087.001 2 reports
- T1087.002 2 reports
- T1090.003 2 reports
- T1095 2 reports
- T1105 2 reports
- T1133 2 reports
- T1135 2 reports
- T1140 2 reports
- T1190 2 reports
- T1201 2 reports
- T1204.002 2 reports
- T1210 2 reports
- T1217 2 reports
- T1482 2 reports
- T1486 2 reports
- T1490 2 reports
- T1518.001 2 reports
- T1543.002 2 reports
- T1543.003 2 reports
- T1547.001 2 reports
- T1547.009 2 reports
- T1566.001 2 reports
- T1566.004 2 reports
- T1567.002 2 reports
- T1573.002 2 reports
- T1595.002 2 reports
- T1003 1 report
- T1003.001 1 report
- T1003.002 1 report
- T1003.003 1 report
- T1005 1 report
- T1007 1 report
- T1008 1 report
- T1010 1 report
- T1012 1 report
- T1016.001 1 report
- T1020 1 report
- T1021 1 report
- T1021.002 1 report
- T1021.005 1 report
- T1021.006 1 report
- T1027 1 report
- T1036 1 report
- T1036.005 1 report
- T1037 1 report
- T1037.001 1 report
- T1039 1 report
- T1040 1 report
- T1041 1 report
- T1047 1 report
- T1048 1 report
- T1048.003 1 report
- T1053 1 report
- T1053.003 1 report
- T1053.005 1 report
- T1055 1 report
- T1055.001 1 report
- T1055.003 1 report
- T1055.004 1 report
- T1055.009 1 report
- T1055.012 1 report
- T1056 1 report
- T1057 1 report
- T1059.002 1 report
- T1059.005 1 report
- T1059.006 1 report
- T1059.007 1 report
- T1059.009 1 report
- T1059.010 1 report
- T1059.011 1 report
- T1069 1 report
- T1069.001 1 report
- T1069.002 1 report
- T1069.003 1 report
- T1070 1 report
- T1071 1 report
- T1071.003 1 report
- T1072 1 report
- T1074 1 report
- T1074.001 1 report
- T1074.002 1 report
- T1078.002 1 report
- T1078.003 1 report
- T1082 1 report
- T1087.004 1 report
- T1090 1 report
- T1090.001 1 report
- T1090.002 1 report
- T1091 1 report
- T1098 1 report
- T1098.001 1 report
- T1098.003 1 report
- T1098.004 1 report
- T1098.005 1 report
- T1098.006 1 report
- T1098.007 1 report
- T1102 1 report
- T1102.002 1 report
- T1104 1 report
- T1110.002 1 report
- T1110.004 1 report
- T1113 1 report
- T1114 1 report
- T1114.001 1 report
- T1114.002 1 report
- T1114.003 1 report
- T1115 1 report
- T1119 1 report
- T1120 1 report
- T1123 1 report
- T1124 1 report
- T1125 1 report
- T1129 1 report
- T1132 1 report
- T1132.001 1 report
- T1134 1 report
- T1134.001 1 report
- T1136 1 report
- T1136.001 1 report
- T1136.002 1 report
- T1137 1 report
- T1137.006 1 report
- T1189 1 report
- T1195 1 report
- T1195.002 1 report
- T1199 1 report
- T1200 1 report
- T1203 1 report
- T1204 1 report
- T1204.001 1 report
- T1213 1 report
- T1213.001 1 report
- T1213.002 1 report
- T1213.003 1 report
- T1484 1 report
- T1484.001 1 report
- T1485 1 report
- T1491.002 1 report
- T1496 1 report
- T1497 1 report
- T1497.001 1 report
- T1498 1 report
- T1505 1 report
- T1505.003 1 report
- T1505.004 1 report
- T1518 1 report
- T1529 1 report
- T1530 1 report
- T1534 1 report
- T1537 1 report
- T1538 1 report
- T1543 1 report
- T1543.004 1 report
- T1546 1 report
- T1546.003 1 report
- T1546.004 1 report
- T1546.008 1 report
- T1546.012 1 report
- T1546.015 1 report
- T1547 1 report
- T1547.002 1 report
- T1547.005 1 report
- T1548 1 report
- T1548.002 1 report
- T1550 1 report
- T1550.001 1 report
- T1550.002 1 report
- T1554 1 report
- T1556 1 report
- T1556.006 1 report
- T1556.009 1 report
- T1558.003 1 report
- T1559 1 report
- T1560 1 report
- T1560.001 1 report
- T1560.002 1 report
- T1565 1 report
- T1565.001 1 report
- T1566 1 report
- T1566.002 1 report
- T1566.003 1 report
- T1567 1 report
- T1567.001 1 report
- T1568.002 1 report
- T1569 1 report
- T1569.002 1 report
- T1570 1 report
- T1571 1 report
- T1573 1 report
- T1573.001 1 report
- T1574 1 report
- T1574.001 1 report
- T1574.011 1 report
- T1578 1 report
- T1580 1 report
- T1583 1 report
- T1583.003 1 report
- T1584 1 report
- T1585 1 report
- T1585.002 1 report
- T1587 1 report
- T1587.001 1 report
- T1587.003 1 report
- T1588 1 report
- T1588.003 1 report
- T1588.004 1 report
- T1588.007 1 report
- T1590.002 1 report
- T1595 1 report
- T1595.003 1 report
- T1598 1 report
- T1602 1 report
- T1602.001 1 report
- T1602.002 1 report
- T1608 1 report
- T1608.001 1 report
- T1608.002 1 report
- T1608.003 1 report
- T1608.004 1 report
- T1608.005 1 report
- T1608.006 1 report
- T1613 1 report
- T1614 1 report
- T1614.001 1 report
- T1615 1 report
- T1619 1 report
- T1620 1 report
- T1622 1 report
- T1649 1 report
- T1652 1 report
- T1654 1 report
- T1657 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2010-0738 KEV ransomware
- CVE-2012-5687
- CVE-2013-3660 KEV
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0057
- CVE-2015-0554
Show all 89 CVEs Show fewer
- CVE-2015-1701 KEV ransomware
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-7255 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2018-0798 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-15982 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-1069 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-3529
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26855 KEV ransomware
- CVE-2021-28482
- CVE-2021-30116 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-42278 KEV ransomware
- CVE-2021-42287 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-26923 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-28252 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-42115
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-23108
- CVE-2024-23109
- CVE-2024-23113 KEV
- CVE-2024-24919 KEV ransomware
- CVE-2024-25600
- CVE-2024-26169 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-37085 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-9474 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor RagnarLocker (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SamSam (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DanaBot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
TA2101, Maze Team - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TA2101, Maze Team - Threat Group Cards: A Threat Actor Encyclopedia
Show all 167 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maze (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Egregor (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor LockBit (Malware Family)
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
An Empirically Comparative Analysis of Ransomware Binaries
The original link failed its last check. Original publisher Detailsfor An Empirically Comparative Analysis of Ransomware Binaries
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
Ransomware Actors Evolved Their Operations in 2020
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Actors Evolved Their Operations in 2020
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
Ransom Mafia - Analysis of the World's First Ransomware Cartel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransom Mafia - Analysis of the World's First Ransomware Cartel
-
So Unchill Melting UNC2198 ICEDID to Ransomware Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor So Unchill Melting UNC2198 ICEDID to Ransomware Operations
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
IcedID Stealer Man-in-the-browser Banking Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IcedID Stealer Man-in-the-browser Banking Trojan
-
Double Trouble- Ransomware with Data Leak Extortion, Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 2
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Egregor Ransomware
-
wp-spark-state-of-ransomware.pdf
The original link failed its last check. Original publisher Detailsfor wp-spark-state-of-ransomware.pdf
-
The original link failed its last check. Original publisher Detailsfor Talks - BrightTALK
-
How to Deobfuscate Maze Ransomware | CrowdStrike
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor How to Deobfuscate Maze Ransomware | CrowdStrike
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sekhmet Ransomware
-
New version of IcedID Trojan uses steganographic payloads
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New version of IcedID Trojan uses steganographic payloads
-
Allied Universal Breached by Maze Ransomware, Stolen Data Leaked
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Allied Universal Breached by Maze Ransomware, Stolen Data Leaked
-
TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
Newest first. Details opens the report in Explore.