[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/threat-brief-maze-ransomware-activities/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/threat-brief-maze-ransomware-activities/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Threat Brief: Maze Ransomware

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 5 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Doel Santos](https://unit42.paloaltonetworks.com/author/doel-santos/)
  * [Brittany Barbehenn](https://unit42.paloaltonetworks.com/author/brittany-barbehenn/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 8, 2020

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Maze](https://unit42.paloaltonetworks.com/tag/maze/)
  * [SpelevoEK](https://unit42.paloaltonetworks.com/tag/spelevoek/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/threat-brief-maze-ransomware-activities/?pdf=download&lg=en&_wpnonce=0e33cfdd78 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/threat-brief-maze-ransomware-activities/?pdf=print&lg=en&_wpnonce=0e33cfdd78 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Threat%20Brief:%20Maze%20Ransomware&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-maze-ransomware-activities%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-maze-ransomware-activities%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-maze-ransomware-activities%2F&title=Threat%20Brief:%20Maze%20Ransomware "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-maze-ransomware-activities%2F&text=Threat%20Brief:%20Maze%20Ransomware "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-maze-ransomware-activities%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Threat%20Brief:%20Maze%20Ransomware%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-brief-maze-ransomware-activities%2F "Share in Mastodon")

## Executive Summary

Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the [Unit 42 Playbook Viewer](https://pan-unit42.github.io/playbook_viewer/?pb=maze-ransomware).

Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized Word or Excel attachments. However, it has also been distributed via exploit kits such as the [Spelevo](https://securityboulevard.com/2020/04/maze-ransomware-are-you-vulnerable/) Exploit Kit, which has been used with Flash Player vulnerabilities [CVE-2018-15982](https://nvd.nist.gov/vuln/detail/CVE-2018-15982) and [CVE-2018-4878](https://nvd.nist.gov/vuln/detail/CVE-2018-4878). Maze ransomware has also utilized [exploit](https://www.darkreading.com/threat-intelligence/maze-ransomware-operators-step-up-their-game/d/d-id/1337756)s [CVE-2019-11510](https://nvd.nist.gov/vuln/detail/CVE-2019-11510) (Pulse VPN), as well as [CVE-2018-8174](https://nvd.nist.gov/vuln/detail/CVE-2018-8174) (Internet Explorer) to get into a network. The malware first establishes a foothold within the environment. It then obtains elevated privileges, conducts lateral movement, and begins file encryption across all drives. However, before encrypting the data, these operators may exfiltrate the files to be used for further coercion, including public exposure. Without the proper protections in place, a Maze ransomware infection will cripple normal business operations, and sensitive information will be compromised, resulting in a monetary loss.

Maze has not only been observed globally, but also affecting varying industries, which include: finance, technology, telecommunications, healthcare, government, construction, hospitality, media and communications, utilities and energy, pharma and life sciences, education, insurance, wholesale, and legal. On March 26, 2020, McAfee published a [report](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/ransomware-maze/) providing a detailed overview of the Maze ransomware.

Palo Alto Networks Cortex XDR contains an [Anti-Ransomware Protection](https://docs.paloaltonetworks.com/traps/4-2/traps-endpoint-security-manager-admin/malware-protection/manage-malware-protection-rules/configure-anti-ransomware-protection) module, which targets encryption-based activities associated with ransomware. Customers can also review activity associated with this Threat Brief via AutoFocus.

## Impact Assessment

Several adversarial techniques were observed in this activity.

The following measures are suggested within [Palo Alto Networks](https://www.paloaltonetworks.com/) products and services for Maze ransomware:

|-----------------------------------------------------------------|---------------------------------------------------------------------------------------------|---------------------|---------------------------------------------------------------------------------------------------------------------------------------------------|
| **Tactic**                                                      | **Technique** **(Mitre ATT\&CK ID)**                                                        | **Product/Service** | **Course of Action**                                                                                                                              |
| Initial Access                                                  | External Remote Services ([T1133](https://attack.mitre.org/techniques/T1133/))              | NGFW                | Configure Interfaces and Zone segmentation                                                                                                        |
| Initial Access                                                  | External Remote Services ([T1133](https://attack.mitre.org/techniques/T1133/))              | Threat Prevention†  | Deploy Vulnerability Protection Profile for all low and high severity threats with block action                                                   |
| Initial Access                                                  | External Remote Services ([T1133](https://attack.mitre.org/techniques/T1133/))              | Cortex XDR          | Configure Host Firewall Profile                                                                                                                   |
| Initial Access                                                  | Spear-Phishing Attachment ([T1193](https://attack.mitre.org/techniques/T1193/))             | NGFW                | Configure a File Blocking Profile                                                                                                                 |
| Initial Access                                                  | Spear-Phishing Attachment ([T1193](https://attack.mitre.org/techniques/T1193/))             | Threat Prevention†  | Enable Anti-Virus profile with reset-both action                                                                                                  |
| Initial Access                                                  | Spear-Phishing Attachment ([T1193](https://attack.mitre.org/techniques/T1193/))             | WildFire            | Forward files for WildFire Analysis                                                                                                               |
| Initial Access                                                  | Spear-Phishing Attachment ([T1193](https://attack.mitre.org/techniques/T1193/))             | Cortex XDR          | Configure Malware Security Profile                                                                                                                |
| Initial Access                                                  | Drive-by Compromise ([T1189](https://attack.mitre.org/techniques/T1189/))                   | NGFW                | Block all unknown and unauthorized applications                                                                                                   |
| Initial Access                                                  | Drive-by Compromise ([T1189](https://attack.mitre.org/techniques/T1189/))                   | Threat Prevention†  | Deploy Vulnerability Protection Profile for all low and high severity threats with block action                                                   |
| Initial Access                                                  | Drive-by Compromise ([T1189](https://attack.mitre.org/techniques/T1189/))                   | DNS Security†       | Enable DNS Security in Anti-Spyware profile                                                                                                       |
| Initial Access                                                  | Drive-by Compromise ([T1189](https://attack.mitre.org/techniques/T1189/))                   | URL Filtering†      | Control web access based on URL Category                                                                                                          |
| Initial Access                                                  | Drive-by Compromise ([T1189](https://attack.mitre.org/techniques/T1189/))                   | WildFire            | Forward Files for WildFire Analysis                                                                                                               |
| Initial Access                                                  | Trusted Relationship ([T1199](https://attack.mitre.org/techniques/T1199/))                  | NGFW                | Configure Interfaces and Zones segmentation                                                                                                       |
| Initial Access Privilege Escalation Persistence Defense Evasion | Valid Accounts ([T1078](https://attack.mitre.org/techniques/T1078/))                        | NGFW                | Configure Multi-Factor Authentication                                                                                                             |
| Initial Access Privilege Escalation Persistence Defense Evasion | Valid Accounts ([T1078](https://attack.mitre.org/techniques/T1078/))                        | Threat Prevention†  | Enable Credential Phishing protection                                                                                                             |
| Initial Access Privilege Escalation Persistence Defense Evasion | Valid Accounts ([T1078](https://attack.mitre.org/techniques/T1078/))                        | Cortex XSOAR        | Deploy Cortex XSOAR Playbook - Access Investigation                                                                                               |
| Execution Defense Evasion                                       | Scripting ([T1064](https://attack.mitre.org/techniques/T1064/))                             | WildFire            | Forward Files for WildFire Analysis                                                                                                               |
| Execution Defense Evasion                                       | Scripting ([T1064](https://attack.mitre.org/techniques/T1064/))                             | Cortex XDR          | Enable Anti-Exploit and Anti-Malware Protection                                                                                                   |
| Execution                                                       | Powershell ([T1086](https://attack.mitre.org/techniques/T1086/))                            | Cortex XDR          | Enable Anti-Exploit and Anti-Malware Protection                                                                                                   |
| Execution                                                       | Command-Line Interface ([T1059](https://attack.mitre.org/techniques/T1059/))                | Cortex XDR          | Enable Anti-Exploit and Anti-Malware Protection                                                                                                   |
| Execution                                                       | Service Execution ([T1035](https://attack.mitre.org/techniques/T1035/))                     | Cortex XDR          | Configure Behavioral Threat Protection under the Malware Security Profile                                                                         |
| Persistence                                                     | Modify Existing Service ([T1031](https://attack.mitre.org/techniques/T1031/))               | Cortex XDR          | Configure Behavioral Threat Protection under the Malware Security Profile                                                                         |
| Persistence                                                     | Registry Run Keys / Startup Folder ([T1060](https://attack.mitre.org/techniques/T1060/))    | Cortex XDR          | Configure Behavioral Threat Protection under the Malware Security Profile                                                                         |
| Persistence                                                     | New Service ([T1050](https://attack.mitre.org/techniques/T1050/))                           | Cortex XDR          | Configure Behavioral Threat Protection under the Malware Security Profile                                                                         |
| Privilege Escalation                                            | Exploitation for Privilege Escalation ([T1068](https://attack.mitre.org/techniques/T1068/)) | Cortex XDR          | Enable Anti-Exploit and Anti-Malware Protection                                                                                                   |
| Defense Evasion                                                 | NTFS File Attributes ([T1096](https://attack.mitre.org/techniques/T1096/))                  | NGFW                | Block all unknown and unauthorized applications                                                                                                   |
| Defense Evasion                                                 | NTFS File Attributes ([T1096](https://attack.mitre.org/techniques/T1096/))                  | WildFire            | Forward files for WildFire Analysis                                                                                                               |
| Defense Evasion                                                 | NTFS File Attributes ([T1096](https://attack.mitre.org/techniques/T1096/))                  | Cortex XDR          | Configure Behavioral Threat Protection under the Malware Security Profile                                                                         |
| Defense Evasion                                                 | Obfuscated Files or Information ([T1027](https://attack.mitre.org/techniques/T1027/))       | WildFire            | Forward files for WildFire Analysis                                                                                                               |
| Defense Evasion                                                 | Obfuscated Files or Information ([T1027](https://attack.mitre.org/techniques/T1027/))       | Cortex XDR          | Enable Anti-Exploit and Anti-Malware Protection                                                                                                   |
| Defense Evasion                                                 | Disabling Security Tools ([T1089](https://attack.mitre.org/techniques/T1089/))              | Cortex XDR          | Configure Behavioral Threat Protection under the Malware Security Profile                                                                         |
| Credential Access                                               | Brute Force ([T1110](https://attack.mitre.org/techniques/T1110/))                           | NGFW                | Create a rule to modify the default action for all signatures in the brute force category to block-ip address action                              |
| Credential Access                                               | Credential Dumping ([T1003](https://attack.mitre.org/techniques/T1003/))                    | Cortex XDR          | Cortex XDR monitors for behavioral events and files associated with credential access and exfiltration                                            |
| Lateral Movement                                                | Remote Desktop Protocol ([T1076](https://attack.mitre.org/techniques/T1076/))               | NGFW                | Configure Multi Factor Authentication,Create User Group for Limited Access to Allow List Applications,Configure Interfaces and Zones segmentation |
| Lateral Movement                                                | Remote Desktop Protocol ([T1076](https://attack.mitre.org/techniques/T1076/))               | Cortex XDR          | Configure Host Firewall Profile                                                                                                                   |
| Collection                                                      | Data from Local System ([T1005](https://attack.mitre.org/techniques/T1005/))                | Cortex XDR          | Cortex XDR monitors for behavioral events and files associated with collection activities                                                         |
| Command and Control                                             | Standard Application Layer Protocol ([T1071](https://attack.mitre.org/techniques/T1071))    | NGFW                | Block all unknown and unauthorized applications                                                                                                   |
| Command and Control                                             | Standard Application Layer Protocol ([T1071](https://attack.mitre.org/techniques/T1071))    | DNS Security†       | Deploy Anti-Spyware profiles with block action                                                                                                    |
| Command and Control                                             | Standard Application Layer Protocol ([T1071](https://attack.mitre.org/techniques/T1071))    | Cortex XDR          | Cortex XDR monitors for behavioral events indicative of command and control activity                                                              |
| Command and Control                                             | Remote File Copy ([T1105](https://attack.mitre.org/techniques/T1105/))                      | NGFW                | Block all unknown and unauthorized applications                                                                                                   |
| Command and Control                                             | Remote File Copy ([T1105](https://attack.mitre.org/techniques/T1105/))                      | WildFire            | Forward files for WildFire Analysis                                                                                                               |
| Command and Control                                             | Remote File Copy ([T1105](https://attack.mitre.org/techniques/T1105/))                      | Cortex XDR          | Cortex XDR monitors for behavioral events associated with file creation, staging, and exfiltration                                                |
| Command and Control                                             | Standard Cryptographic Protocol ([T1032](https://attack.mitre.org/techniques/T1032/))       | NGFW                | Block all unknown and unauthorized applications, Enable SSL decryption                                                                            |
| Command and Control                                             | Standard Cryptographic Protocol ([T1032](https://attack.mitre.org/techniques/T1032/))       | DNS Security†       | Enable DNS Security in Anti-Spyware profile                                                                                                       |
| Command and Control                                             | Standard Cryptographic Protocol ([T1032](https://attack.mitre.org/techniques/T1032/))       | WildFire            | Forward SSL decrypted files to WildFire                                                                                                           |
| Discovery                                                       | File and Directory Discovery ([T1083](https://attack.mitre.org/techniques/T1083/))          | Cortex XDR          | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors                                                 |
| Discovery                                                       | Network Share Discovery ([T1135](https://attack.mitre.org/techniques/T1135))                | Cortex XDR          | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors                                                 |
| Discovery                                                       | Process Discovery ([T1057](https://attack.mitre.org/techniques/T1057))                      | Cortex XDR          | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors                                                 |
| Discovery                                                       | Software Discovery ([T1518](https://attack.mitre.org/techniques/T1518))                     | Cortex XDR          | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors                                                 |
| Discovery                                                       | System Information Discovery ([T1082](https://attack.mitre.org/techniques/T1082))           | Cortex XDR          | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors                                                 |
| Exfiltration                                                    | Data Encrypted ([T1022](https://attack.mitre.org/techniques/T1022))                         | Cortex XDR          | Configure Behavioral Threat Protection under the Malware Security Profile                                                                         |
| Exfiltration                                                    | Exfiltration Over Alternative Protocol ([T1048](https://attack.mitre.org/techniques/T1048)) | NGFW          | Block all unknown and unauthorized applications. profile                                                                                          |
| Exfiltration                                                    | Exfiltration Over Alternative Protocol ([T1048](https://attack.mitre.org/techniques/T1048)) | DNS Security†       | Enable DNS Security in Anti-Spyware                                                                                                               |
| Exfiltration                                                    | Exfiltration Over Command and Control ([T1041](https://attack.mitre.org/techniques/T1041))  | NGFW                | Block all unknown and unauthorized applications                                                                                                   |
| Exfiltration                                                    | Exfiltration Over Command and Control ([T1041](https://attack.mitre.org/techniques/T1041))  | DNS Security†       | Enable DNS Security in the Anti-Spyware profile                                                                                                   |
| Exfiltration                                                    | Exfiltration Over Command and Control ([T1041](https://attack.mitre.org/techniques/T1041))  | Threat Prevention†  | Enable Anti-Spyware Profile with Block Action                                                                                                     |
| Impact                                                          | Data Encrypted for Impact ([T1486](https://attack.mitre.org/techniques/T1486))              | Cortex XSOAR        | Deploy Cortex XSOAR Playbook - Ransomware Manual for incident response                                                                            |

*Table 1. Course of Action for Maze Ransomware* ^†^These capabilities are part of the NGFW security subscriptions service

Recently, malicious operators behind the Maze ransomware activities compromised multiple [IT service providers](https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/). These operators were also able to establish a foothold within another victim's network through insecure Remote Desktop Protocol and [other remote service](https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html) connections or by brute-forcing the local administrator account. Organizations should be mindful of potential compromises through third-party sources and ensure strong passwords are used for all systems capable of remote access.

It was also [reported](https://www.bleepingcomputer.com/news/security/ransomware-attackers-use-your-cloud-backups-against-you/) that Maze operators pay special attention to cloud backups on the compromised network. If the operators were to obtain login credentials, they are then able to download all backup data to an actor controlled server. Organizations should ensure that all cloud backup files are properly stored and protected.

**Threat Education**

What is Ransomware?

Ransomware is a criminal business model that uses malicious software to hold valuable files and other data for ransom. Victims of ransomware attacks may have their operations degraded or shut down entirely.

For additional details on a *What is Ransomware?* , visit the Palo Alto Networks Cyberpedia:  
[https://www.paloaltonetworks.com/cyberpedia/what-is-ransomware](https://www.paloaltonetworks.com/cyberpedia/what-is-ransomware)

Palo Alto Networks customers can review activity associated with this Threat Brief via [AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus) using the following tag: [*Maze*](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Maze), [SpelevoEKFlashContainer](https://autofocus.paloaltonetworks.com/#/tag/Unit42.SpelevoEKFlashContainer)

Palo Alto Networks Cortex [XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) contains an Anti-Ransomware Protection module. This module targets encryption-based activity associated with ransomware. Cortex XDR contains defined [behavioral indicators of compromise](https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators.html) designed to detect anomalies within your network.

More information on ransomware can be found in the [2021 Unit 42 Ransomware Threat Report](https://start.paloaltonetworks.com/unit-42-ransomware-threat-report).

**References**

[https://download.bitdefender.com/resources/files/News/CaseStudies/study/318/Bitdefender-TRR-Whitepaper-Maze-creat4351-en-EN-GenericUse.pdf](https://download.bitdefender.com/resources/files/News/CaseStudies/study/318/Bitdefender-TRR-Whitepaper-Maze-creat4351-en-EN-GenericUse.pdf)  
[https://www.docdroid.net/dUpPY5s/maze-pdf#page=2](https://www.docdroid.net/dUpPY5s/maze-pdf#page=2)

*The suggested courses of action in this report are based on the information currently available to Palo Alto Networks and the capabilities within Palo Alto Networks products and services.*
Back to top

### Tags

* [Maze](https://unit42.paloaltonetworks.com/tag/maze/ "Maze")
* [SpelevoEK](https://unit42.paloaltonetworks.com/tag/spelevoek/ "SpelevoEK")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: SilverTerrier: New COVID-19 Themed Business Email Compromise Schemes](https://unit42.paloaltonetworks.com/silverterrier-covid-19-themed-business-email-compromise/ "SilverTerrier: New COVID-19 Themed Business Email Compromise Schemes")

### Table of Contents

* 

### Related Articles

* [Highlights from the 2021 Unit 42 Ransomware Threat Report](https://unit42.paloaltonetworks.com/ransomware-threat-report-highlights/ "article - table of contents")

## Related Ransomware Resources

![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Constellation image representing the constellation schema used by Palo Alto Networks Unit 42 to track nation-state and cybercrime threat actor groups](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/Generic-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 1, 2025 [#### Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/)

* [Academic Serpens](https://unit42.paloaltonetworks.com/tag/academic-serpens/ "Academic Serpens")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agonizing Serpens](https://unit42.paloaltonetworks.com/tag/agonizing-serpens/ "Agonizing Serpens")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) July 31, 2025 [#### Introducing Unit 42's Attribution Framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/tag/bookworm/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/ "Introducing Unit 42’s Attribution Framework")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![A pictorial representation of Akira ransomware, distributed by Howling Scorpius. A person's hand typing on a keyboard with a digital screen displaying the word "password" highlighted in blue, set against a backdrop of various cybersecurity interface graphics.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/09_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) December 2, 2024 [#### Threat Assessment: Howling Scorpius (Akira Ransomware)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/)

* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")

* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")

* [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/ "torrenting")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/ "Threat Assessment: Howling Scorpius (Akira Ransomware)")  
  ![Pictorial representation of a threat like BlackSuit ransomware. An illustration of a modern workspace with a laptop displaying cybersecurity icons, surrounded by stacks of coins and a credit card, all depicted in a neon, digital art style.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/04_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) November 20, 2024 [#### Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/)

* [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/ "BlackSuit ransomware")

* [Construction](https://unit42.paloaltonetworks.com/tag/construction/ "construction")

* [Education](https://unit42.paloaltonetworks.com/tag/education/ "Education")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/ "Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware")  
  ![A representation of a threat group like Jumpy Pisces. Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) October 30, 2024 [#### Jumpy Pisces Engages in Play Ransomware](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/ "Jumpy Pisces Engages in Play Ransomware")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
