Makop is a human-operated ransomware operation active since 2020 and generally treated as a Phobos-derived ransomware family. It has operated as part of the broader ransomware affiliate ecosystem and has been advertised alongside other ransomware groups on Russian-language cybercrime forums. Makop has also been associated with family variants such as Ndm448. Makop commonly gains initial access through exposed Remote Desktop Protocol services, including brute-force and dictionary attacks against weak or reused credentials, and has also been linked to the abuse of exposed remote administration services and internet-facing vulnerabilities. Reported intrusions show a hands-on-keyboard workflow in which operators stage tooling, enumerate the environment, escalate privileges, disable security controls, steal credentials, move laterally, and then deploy ransomware. Observed tradecraft includes network and port scanning, credential dumping, abuse of legitimate administrative utilities, and use of custom .NET tooling for persistence and credential operations. The group’s toolkit combines off-the-shelf software with custom malware. Public reporting has described custom tools including ARestore, used to generate and test local Windows credential combinations, and PuffedUp, a persistence utility. Makop operators have also used PsExec for lateral movement; Mimikatz, LaZagne, and NetPass for credential theft; Process Hacker and similar utilities to terminate security products; and scanning or discovery tools such as NetScan, Advanced IP Scanner, Advanced Port Scanner, Masscan, and Everything. Additional reporting links Makop intrusions to GuLoader as a delivery mechanism in some cases. Makop has repeatedly demonstrated defense-evasion and privilege-escalation capability. Operators have been observed disabling Microsoft Defender, attempting to uninstall endpoint protection products, and using bring-your-own-vulnerable-driver techniques with vulnerable signed drivers to gain kernel-level access and interfere with security tooling. Reporting also ties Makop activity to local privilege-escalation exploits affecting Windows. In some incidents, operators reportedly aborted attacks when their tooling was detected, indicating opportunistic but adaptive operations. Makop campaigns have included double-extortion behavior. The Ndm448 variant, assessed as part of the Makop family, has been described as encrypting local and network-accessible data while claiming prior theft of sensitive information and threatening disclosure or sale of stolen data. Makop activity has targeted organizations in multiple countries, with reporting specifically identifying India, Brazil, Germany, South Korea, and victims in Europe including Italy. The victimology and intrusion patterns indicate primarily financially motivated, opportunistic ransomware operations rather than a narrowly scoped geopolitical mission.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Mentioned as one of several ransomware families using PsExec and NirSoft; also referenced with exposed RDP as an initial access route.
Referenced as a ransomware operation previously associated with BYOVD attacks using the same vulnerable drivers discussed in the article.
Ransomware operators observed using Process Hacker to support attacks by disabling or interfering with security tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.