Maui ransomware represents a sophisticated file-encryption threat that has targeted healthcare organizations and critical infrastructure sectors since mid-2021. Unlike commodity ransomware that spreads indiscriminately, Maui operates through manual, hands-on-keyboard deployment by threat actors who've already gained privileged access to your network. This makes it particularly dangerous—by the time Maui executes, attackers have typically been inside your systems for days or weeks, mapping your data and disabling your defenses.
If you're reading this because files on your computer suddenly have strange extensions and you're seeing a ransom note, understand that Maui infection represents the final stage of a broader network compromise. The good news: Maui doesn't delete shadow copies or use Windows restart procedures like some ransomware families, which can improve recovery chances. The bad news: professional remediation is essential because the initial access vector likely remains active.
Threat Profile
| Threat Name | Maui Ransomware |
| Threat Type | Ransomware (File Encryptor), Manually Deployed |
| Platform | Windows (PE32/PE32+ executable) |
| First Observed | May 2021 (public reporting July 2022) |
| Primary Targets | Healthcare organizations, critical infrastructure (U.S. focus) |
| Attribution | North Korean state-sponsored threat actors (CISA advisory) |
| Encryption Method | AES-128 with RSA-2048 key encryption |
| File Extension | .maui (appended to encrypted files) |
| Ransom Note | readme.txt (dropped in encrypted directories) |
| Data Exfiltration | Not a primary feature (encryption-focused) |
| Detection Names | Ransom.Maui, HEUR:Trojan-Ransom.Win32.Generic, Trojan.Ransom.Maui |
| Severity Assessment | High (manual deployment, sophisticated threat actor, healthcare targeting) |
How It Spreads
Maui doesn't arrive through traditional infection vectors like phishing emails or malicious advertisements. Instead, threat actors gain initial access through exploited vulnerabilities in public-facing applications, compromised remote desktop services, or stolen credentials. Once inside your network, they conduct extensive reconnaissance—sometimes over weeks or months—identifying valuable data, backup locations, and administrative accounts. Only after this preparation phase do they manually deploy Maui across selected systems.
The deliberate, human-operated nature of Maui deployment means infections follow predictable patterns within organizations but vary significantly in initial compromise methods. Healthcare facilities have been disproportionately targeted, likely because attackers know medical data and system availability represent critical pressure points for ransom payment. The absence of automated spreading mechanisms actually makes Maui more dangerous—every action is calculated and custom-tailored to maximize damage.
Common entry points and deployment methods include:
- Exploited VPN or remote desktop vulnerabilities — Unpatched Fortinet, Pulse Secure, or Citrix gateways provide initial footholds
- Credential theft and abuse — Previously compromised passwords purchased from dark web markets or obtained through information-stealing malware
- Lateral movement via PsExec and WMI — Attackers use Windows administrative tools to copy Maui executables across networked systems
- Scheduled tasks and services — Maui deployment often involves creating scheduled tasks for persistence and execution timing
- Disabled security software — Prior to encryption, attackers manually disable antivirus, EDR solutions, and monitoring systems using administrative access
What It Does On Your Machine
Once executed, Maui operates with surgical precision. Unlike noisy ransomware that encrypts everything indiscriminately, Maui uses command-line arguments to specify exactly which files or directories to target. The ransomware accepts parameters for target paths and encryption keys, meaning each deployment is configured by the operator. This targeted approach helps avoid system instability while maximizing impact on valuable data. The encryption itself uses industry-standard AES-128 in CBC mode, with unique encryption keys for each file that are then encrypted with a hardcoded RSA-2048 public key.
What makes Maui particularly insidious is its minimalist approach. It doesn't crash systems, display flashy lock screens, or automatically spread. It simply encrypts specified files, appends the .maui extension, and drops a readme.txt file containing ransom instructions. This restraint serves the attackers' interests—keeping systems partially functional maintains pressure on victims while preserving the attackers' access for potential follow-up extortion or data theft. The lack of data wiper functionality and careful file targeting suggests financially motivated operators rather than pure destructive intent.
On an infected system, you'll observe several forensic artifacts that distinguish Maui from other ransomware families:
Because Maui deployment follows manual reconnaissance, you may also find evidence of pre-encryption activity: recently created administrative accounts, unusual network scanning traffic, disabled backup services, or cleared event logs. These indicators help forensic investigators piece together the full attack timeline, which is critical for determining whether data was exfiltrated and ensuring complete threat actor eviction from your network.
Manual Removal — Step by Step
Isolate the infected machine immediately
Disconnect from all networks—wired and wireless—but do not power down. Maui is manually deployed, meaning threat actors may still have active access to your network. Keeping the infected machine running preserves volatile memory evidence. If you're on a business network, notify your IT security team before proceeding further. Document exactly when you first noticed the infection.
Boot into Safe Mode with Networking
Restart the computer and press F8 (or Shift+F8 on newer systems) during boot to access Advanced Boot Options. Select "Safe Mode with Networking." This loads Windows with minimal drivers and services, preventing most malware from executing while maintaining internet access for downloading removal tools. On Windows 10/11, you may need to interrupt the boot process three times to trigger automatic repair, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart > F5 for Safe Mode with Networking.
Run a comprehensive anti-malware scan
Download and run Malwarebytes (free version available) and perform a full system scan. Also run Windows Defender Offline Scan (built into Windows Security settings) for a second opinion. Maui executables themselves are typically detected as Ransom.Maui or similar variants, but the initial access tools and backdoors threat actors used to deploy it may have generic detection names. Remove all detected threats, but understand this addresses symptoms rather than root causes—professional forensics are needed to confirm complete eradication.
Search for persistence mechanisms
Open Task Scheduler (taskschd.msc) and review all scheduled tasks, especially those running from AppData, Temp, or ProgramData folders. Delete any unfamiliar tasks. Next, run msconfig and check the Startup tab for suspicious entries. Use Autoruns from Sysinternals (Microsoft tool) for comprehensive startup location analysis. Remove any entries pointing to executables in unusual locations or with generic names like "update.exe" or "svchost.exe" outside System32.
Check for unauthorized user accounts
Open Computer Management > Local Users and Groups > Users. Look for recently created accounts you don't recognize, especially those in the Administrators group. Threat actors often create backdoor accounts during the reconnaissance phase. Document any suspicious accounts (note creation dates) before deleting them. Also review Group Policy settings (gpedit.msc) for modifications that might facilitate continued access.
Assess file encryption damage
Navigate through your important directories and document which files have the .maui extension. Take screenshots of ransom notes before removing them—these contain information potentially useful to law enforcement. Check if Windows Volume Shadow Copies exist (vssadmin list shadows in Command Prompt as administrator). Maui typically doesn't delete these, unlike many ransomware families, which creates potential recovery opportunities.
Attempt file recovery from shadow copies
If shadow copies exist, use ShadowExplorer (free third-party tool) or the native Previous Versions feature (right-click folders > Properties > Previous Versions) to restore pre-encryption versions of critical files. This won't work for all files and depends on restore point timing, but can salvage important recent documents. For business systems, restoration from offline backup media is strongly preferred—shadow copies may have been compromised during the reconnaissance phase.
Change all passwords from a clean device
Using a different, known-clean computer or phone, change passwords for all accounts accessible from the infected machine—especially email, banking, cloud storage, and administrative accounts. Enable two-factor authentication everywhere possible. The threat actors likely harvested credentials during their reconnaissance, so password resets are mandatory even if you successfully remove the malware.
Consider professional forensics and clean reinstallation
For small business or critical home systems, strongly consider wiping the drive and performing a clean Windows reinstallation rather than trusting malware removal. Maui deployment indicates sophisticated threat actor access, and hidden backdoors may persist even after apparent cleaning. Professional forensics can identify the initial compromise vector, determine if data was exfiltrated, and provide evidence for insurance claims or law enforcement. At Computer Repair Roswell, we perform disk imaging before cleanup to preserve evidence while restoring your system.
Report to authorities and implement monitoring
File a report with the FBI's Internet Crime Complaint Center (IC3.gov) and provide details to CISA if you're a healthcare or critical infrastructure organization. Install and configure comprehensive endpoint detection and response (EDR) software, not just traditional antivirus. Enable Windows Security features like ransomware protection and controlled folder access. Establish a routine backup schedule with offline or cloud backups using the 3-2-1 rule (three copies, two media types, one offsite).
Prevention
- Implement network segmentation and zero-trust architecture — Maui spreads through lateral movement after initial compromise. Segment your network so workstations can't directly access servers, and require authentication for every resource access. This limits how far attackers can move even if they breach perimeter defenses.
- Maintain aggressive patch management for internet-facing systems — VPN appliances, remote desktop gateways, and web applications represent prime targets. Subscribe to vendor security bulletins and apply critical patches within 72 hours. For small businesses without dedicated IT staff, consider managed security service providers who monitor vulnerabilities.
- Enforce strong authentication with multi-factor everywhere — Mandate complex passwords (14+ characters, not dictionary words) and enable MFA for all remote access, email, cloud services, and administrative accounts. Use hardware security keys (like YubiKey) for high-privilege accounts. Credential theft enabled many Maui deployments—MFA significantly raises attacker costs.
- Establish comprehensive backup procedures with offline copies — Follow the 3-2-1 backup rule religiously. Keep at least one backup copy completely offline or in immutable cloud storage that prevents deletion even with administrative credentials. Test restoration procedures quarterly—untested backups are just expensive optimism.
- Deploy endpoint detection and response (EDR) with behavioral monitoring — Traditional antivirus signature-matching won't catch sophisticated manually-deployed threats. EDR solutions monitor for behavioral indicators like lateral movement attempts, credential dumping, or unusual encryption activity. For home users, Windows Defender with all features enabled provides baseline protection, but business environments need enterprise-grade solutions.
- Restrict administrative privileges to absolute minimum necessary — Users should operate with standard accounts for daily work. Administrative credentials should require separate login and be used only when specifically needed. Threat actors can't deploy Maui without administrative access, so privilege management directly reduces attack surface.
- Enable comprehensive logging and establish security monitoring — Configure Windows Event Logging to capture authentication attempts, process creation, PowerShell execution, and network connections. Forward logs to a secure external system or SIEM solution. Maui operators spend days or weeks inside networks before striking—proper monitoring creates detection opportunities during reconnaissance phases.
- Conduct employee security awareness training focused on credential protection — While Maui doesn't arrive via phishing, the initial access often does. Train employees to recognize social engineering, use password managers, report suspicious emails without opening attachments, and understand that IT will never ask for passwords. Quarterly training with simulated phishing tests significantly improves organizational security posture.
Bring It In
Maui ransomware represents the nightmare scenario: sophisticated threat actors with days or weeks of access to your system before you even know they're there. While the manual removal steps above can address surface-level infection, they cannot answer the critical questions that determine your real security posture. Were credentials exfiltrated? Did attackers access your email or financial accounts? What vulnerability gave them initial access, and is it still exploitable? Are backdoors still present waiting for the next deployment? These questions require forensic expertise, not just malware scanning.
At Computer Repair Roswell, we approach ransomware cases with the seriousness they deserve. We perform complete disk imaging to preserve evidence before any remediation work. We identify the initial compromise vector so it can be permanently closed. We verify complete threat actor eviction, not just malware removal. And we implement layered security measures—proper backups, authentication hardening, monitoring solutions—to prevent reinfection. Don't trust your business data or personal files to automated removal tools when a sophisticated threat actor has targeted your system. Call us at (770) 856-1525 or bring your computer to our Roswell shop at 1394 Canton Road. We're here Monday through Saturday, ready to help you recover from infection and implement the security practices that prevent the next one.