The Makop ransomware, a derivative of the Phobos family, has resurfaced with enhanced capabilities, focusing on exploiting exposed Remote Desktop Protocol (RDP) services.
Security researchers at Acronis have identified that Makop’s operators now combine RDP compromise with off‑the‑shelf tools, local privilege escalation (LPE) exploits, and loader malware to expand their attack chain.
Once attackers gain access via weak or reused RDP credentials, they deploy utilities such as NetScan, Advanced IP Scanner, and Masscan to map the network. These tools help identify active hosts and open ports, enabling lateral movement.
Attackers often rely on credential-dumper tools such as Mimikatz, LaZagne, and NetPass, as well as brute‑force tools such as AccountRestore and NLBrute, to escalate privileges and access multiple systems across the environment.
What makes Makop’s recent operations distinct is the integration of the GuLoader Trojan as a delivery mechanism for additional payloads. GuLoader has previously been seen in campaigns by groups such as Qilin and Rhysida, but this marks its first known association with Makop.
Once executed, GuLoader deploys VBS scripts and multiple encrypted binaries (e.g., .mc_fxt.exe, .mc_p1z.exe) to user directories such as Music or Downloads before installing the ransomware encryptor itself.
Attack Flow and Target Regions
The complete Makop infection chain begins with unauthorized RDP access, proceeds through tool staging, defense evasion, and culminates in encryption.
To evade detection, attackers often disable Windows Defender using tools such as Defender Control and Disable Defender, or remove antivirus software manually using Quick Heal Uninstallers.
They also employ a “bring your own vulnerable driver (BYOVD)” approach, exploiting kernel-level drivers such as ThrottleStop—sys (CVE‑2025‑7771) and hlpdrv.sys to terminate endpoint protection tools.

To gain system privileges, the group abuses a range of public LPE vulnerabilities, including CVE‑2016‑0099, CVE‑2017‑0213, CVE‑2020‑0796, and CVE‑2021‑41379.
Most of these flaws target Windows components such as BITS, Win32k, and SMB drivers, granting attackers administrative or SYSTEM-level access to turn off defenses before file encryption.
Acronis telemetry indicates that over half of all Makop attacks (55%) observed in 2025 targeted organizations in India, with smaller clusters in Brazil and Germany. The use of Region-specific antivirus removers suggests region-adaptive tactics.
Makop’s renewed activity underscores how routine misconfigurations, such as open RDP ports and unpatched Windows systems, can result in a complete network compromise.
Its blend of commodity tools and known exploits represents a low-effort yet potent ransomware model capable of crippling businesses that neglect multifactor authentication and patch hygiene.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates