Skip to content
Updated Makop ransomware emerges

Updated Makop ransomware emerges

Scworld December 11, 2025

Phobos -based Makop ransomware has been improved to include the GuLoader malware for additional payload delivery, as well as leverage multiple off-the-shelf tools to bypass detection, Cyber Security News reports.

Attacks with Makop ransomware, which have been mostly aimed at Indian organizations, commenced with the abuse of Remote Desktop Protocol and brute-force tools for initial access, followed by the delivery of a toolkit with privilege escalation exploits and network scanners, as well as credential-dumping and antivirus disabling tools, for lateral movement, data extraction, and eventual encrypted payload distribution, an Acronis analysis showed.

Researchers have attributed Makop ransomware's success to its extensive local privilege escalation exploit collection, with the flaws, tracked as CVE-2017-0213, CVE-2018-8639, CVE-2021-41379, and CVE-2016-0099, being the most abused in its attacks. Such findings highlight the risks associated with weaponized administrative tools.