Makop is a human-operated ransomware family active since around 2020 and commonly assessed as a Phobos-derived ransomware-as-a-service variant. It primarily targets Windows environments and has been observed compromising organizations through exposed Remote Desktop Protocol services, including brute-force and dictionary attacks against weak credentials, as well as through spearphishing campaigns delivering malicious attachments. Makop activity has affected organizations in multiple regions, including South Korea, India, Brazil, Germany, Europe, and Italy, and has also been reported against critical infrastructure such as water and wastewater entities.
Makop intrusions typically involve substantial hands-on-keyboard post-compromise activity before encryption. Operators stage a toolkit of legitimate and custom utilities for network discovery, credential access, lateral movement, privilege escalation, persistence, and defense evasion. Observed tooling includes scanners and administrative utilities, credential theft tools such as Mimikatz, LaZagne, and NirSoft utilities, remote execution via PsExec, and process-termination or deletion tools such as Process Hacker and IOBit Unlocker. Makop operators have also used custom .NET tools including ARestore, which generates and tests local Windows credential combinations, and PuffedUp, which establishes persistence. Recent reporting also describes use of GuLoader to deliver additional payloads, including Makop, marking an evolution from earlier direct deployment patterns.
Defense evasion and privilege escalation are prominent in Makop operations. Operators have disabled Microsoft Defender, attempted to uninstall security products, and abused bring-your-own-vulnerable-driver techniques to gain kernel-level capability and interfere with endpoint defenses. Multiple Windows local privilege escalation exploits have been associated with Makop intrusions. Recovery inhibition behavior includes deletion of shadow copies and modification of boot settings prior to file encryption. Some variants also add persistence mechanisms before rebooting systems.
Makop has been linked to double-extortion style pressure in some family variants, with ransom notes claiming data theft prior to encryption. Related variants such as Ndm448 encrypt local and accessible network drives, traverse user and system directories extensively, and drop ransom notes while threatening disclosure of stolen data. Across reporting, Makop appears opportunistic rather than narrowly sector-specific, with operators reusing a stable mix of commodity tools and custom malware over several years.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2020-0796 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2020-1066 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2020-0787 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2017-0213 … In our telemetry… CVE-2017-0213… [was] among the most frequently used…”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2018-8639 … In our telemetry… CVE-2018-8639… [was] among the most frequently used…”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2021-41379 … In our telemetry… CVE-2021-41379… [was] among the most frequently used…”
“ThrottleStop.sys is a legitimate, signed driver… The ThrottleStop vulnerability (CVE-2025-7771) comes from the way the driver handles memory access. Attackers can exploit this to gain control, ultimately leading to disabling security tools.”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2019-1388 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2022-24521 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2016-0099 … In our telemetry… CVE-2017-0213, CVE-2018-8639, CVE-2021-41379 and CVE-2016-0099 were among the most frequently used…”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Insights from a recent intrusion authored by Makop ransomware operators show persistence capability through dedicated .NET tools. Makop toolkit includes both off-the-shelf tools and custom-developed ones, including tools from the Chinese underground ecosystem.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon infection, the malware quickly used the WMI command-line (WMIC) utility and deleted shadow copies.
“Discovery T1057 Process Discovery” (Ndm448 list) and also present in UNC3886 list.
“Discovery T1083 File and Directory Discovery” (Ndm448 list) and narrative describing rapid traversal of user/system directories prior to encryption.
“Discovery T1135 Network Share Discovery” (Ndm448 list) and description: “full file encryption across local and accessible network drives”.
570 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Referenced only as prior context for abuse of the IObit Unlocker driver in separate ransomware intrusions.
Ransomware family mentioned as using NirSoft tools and PsExec; exposed RDP with weak credentials is cited as an access path for Makop.
Ransomware family cited as using Process Hacker to support attack activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.