Makop is a financially motivated, human-operated ransomware operation active since 2020 whose encryptor derives from the Phobos ransomware family. Also styled MakOp, the operation has run an affiliate program and recruited participants through cybercriminal forums. Its targeting is opportunistic, with documented attacks against organizations in India, Italy, Brazil, Germany, and South Korea. Ndm448 is a variant of the Makop ransomware family. Makop operators primarily obtain initial access through exposed, poorly secured Remote Desktop Protocol services, using brute-force and dictionary attacks against weak or reused credentials. They have used NLBrute to automate password guessing and RDP and PsExec for lateral movement. Their toolkit combines custom .NET utilities with publicly available software: ARestore generates and tests local Windows credential combinations, while PuffedUp establishes persistence through a Windows startup mechanism. Credential theft tools include Mimikatz, LaZagne, and NirSoft utilities; network and file discovery tools include NetScan, Advanced IP Scanner, Advanced Port Scanner, Masscan, and Everything. GuLoader has also been used to deliver Makop ransomware payloads. The operators exploit Windows local privilege-escalation vulnerabilities and disable endpoint defenses before encryption. Their defense-evasion techniques include packed tools, Microsoft Defender-disabling utilities, tailored antivirus uninstallers, Process Hacker, and kernel-level process hiding with YDArk. Makop intrusions also employ bring-your-own-vulnerable-driver techniques to interfere with security products. The operation relies heavily on hands-on-keyboard activity and tool staging before deploying its encryptor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Mentioned as one of several ransomware families using PsExec and NirSoft; also referenced with exposed RDP as an initial access route.
Mentioned as another ransomware operation associated with abuse of the rwdrv.sys and hlpdrv.sys vulnerable drivers.
Referenced as a ransomware operation previously associated with BYOVD attacks using the same vulnerable drivers discussed in the article.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.