Makop is a human-operated ransomware threat actor and malware family active since 2020, generally assessed as derived from or closely related to Phobos. The group primarily compromises organizations through exposed Remote Desktop Protocol services, often using brute-force or dictionary attacks against weak credentials, and has also leveraged exposed remote administration services and internet-facing vulnerabilities. Makop intrusions are typically hands-on-keyboard operations in which operators stage tooling for discovery, credential access, privilege escalation, defense evasion, lateral movement, persistence, and ransomware deployment before encrypting victim systems. Makop has repeatedly targeted organizations in Europe, including Italy, and has also been observed affecting victims in India, Brazil, Germany, and South Korea. Victimology appears largely opportunistic rather than tightly sector-specific. The actor has used a stable toolkit combining custom .NET utilities with legitimate administrative software and publicly available offensive tools. Reported custom components include ARestore, used to generate and test local Windows credential combinations, and PuffedUp, a persistence utility that establishes autorun execution. Makop operators have also used common dual-use tools such as PsExec, PuTTY, Mimikatz, LaZagne, NetPass, Advanced IP Scanner, Advanced Port Scanner, Masscan, Everything, Process Hacker, and IOBit Unlocker. Operationally, Makop is associated with credential theft, local account abuse, network and port scanning, and lateral movement via PsExec. The group has used brute-force tooling to access additional accounts and has exploited multiple Windows local privilege escalation vulnerabilities. Defense evasion is a notable feature of Makop activity: operators have disabled or attempted to uninstall security products, used packed variants of tools to bypass detections, and employed bring-your-own-vulnerable-driver techniques with vulnerable drivers to gain kernel-level access and interfere with endpoint defenses. Use of YDArk and other kernel-level tooling has also been reported in Makop-related intrusions. Makop campaigns have included both encryption and data theft. The Ndm448 strain, assessed as part of the Makop family, has been linked to double-extortion operations in which data is exfiltrated before encryption and victims are threatened with public disclosure or sale of stolen information. Makop variants have also been observed deleting shadow copies to inhibit recovery. Recent reporting indicates the actor continues to evolve incrementally, including use of loader malware to deliver ransomware payloads, while retaining a largely consistent tradecraft centered on exposed remote access, credential abuse, administrative tooling, and pragmatic defense evasion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as one of several ransomware families using PsExec and NirSoft; also referenced with exposed RDP as an initial access route.
Referenced as a ransomware operation previously associated with BYOVD attacks using the same vulnerable drivers discussed in the article.
Ransomware operators observed using Process Hacker to support attacks by disabling or interfering with security tools.
Ransomware operation/family associated with enterprise-targeted Windows encryption and double-extortion behavior (data theft plus encryption), including shadow copy deletion and broad directory enumeration prior to encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.