Makop is a Windows ransomware family first observed around 2020 and derived from Phobos. It is deployed through a ransomware-as-a-service model and human-operated intrusions, including attacks against small businesses. Its targeting is geographically broad and opportunistic, with documented campaigns affecting South Korea, India, Brazil, Germany, Italy, and Colombia.
Makop encrypts victim files and demands payment for recovery. Observed variants delete Volume Shadow Copies using Windows management utilities and alter boot configuration to hinder recovery. Some variants establish persistence through startup scripts before rebooting. Distribution has included Korean-language spearphishing emails carrying executable attachments disguised as resumes, as well as copyright-related email lures. Operators also gain access through exposed Remote Desktop Protocol services, using brute-force and dictionary attacks against weak or reused credentials. GuLoader has been used to deliver Makop payloads.
Makop operators combine custom .NET tools with legitimate administration utilities and publicly available offensive tools. Their intrusion workflow includes network and file discovery, credential theft, local privilege escalation, lateral movement, and suppression of endpoint defenses before encryption. Tools include Mimikatz, LaZagne, and NirSoft utilities for credential access; PsExec for remote execution and lateral movement; and network scanners for host and service discovery. Custom tools include ARestore for generating and testing local Windows credential combinations and PuffedUp for persistence. Defense evasion includes disabling or uninstalling security software, abusing Process Hacker and IObit Unlocker, hiding processes through kernel manipulation, and bring-your-own-vulnerable-driver techniques against endpoint protection. Operators have also exploited multiple Windows local privilege-escalation vulnerabilities. Makop has been associated with re-extortion, in which attackers demand additional payment after an initial ransom has been paid.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2020-0796 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2020-1066 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2020-0787 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2017-0213 … In our telemetry… CVE-2017-0213… [was] among the most frequently used…”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2018-8639 … In our telemetry… CVE-2018-8639… [was] among the most frequently used…”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2021-41379 … In our telemetry… CVE-2021-41379… [was] among the most frequently used…”
“ThrottleStop.sys is a legitimate, signed driver… The ThrottleStop vulnerability (CVE-2025-7771) comes from the way the driver handles memory access. Attackers can exploit this to gain control, ultimately leading to disabling security tools.”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2019-1388 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2022-24521 …”
“Multiple local privilege escalation (LPE) vulnerabilities… CVE-2016-0099 … In our telemetry… CVE-2017-0213, CVE-2018-8639, CVE-2021-41379 and CVE-2016-0099 were among the most frequently used…”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Group Member “datastore” is suspected to be an ex-member of Makop Ransomware Group.
Insights from a recent intrusion authored by Makop ransomware operators show persistence capability through dedicated .NET tools. Makop toolkit includes both off-the-shelf tools and custom-developed ones, including tools from the Chinese underground ecosystem.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon infection, the malware quickly used the WMI command-line (WMIC) utility and deleted shadow copies.
“Discovery T1057 Process Discovery” (Ndm448 list) and also present in UNC3886 list.
“Discovery T1083 File and Directory Discovery” (Ndm448 list) and narrative describing rapid traversal of user/system directories prior to encryption.
“Discovery T1135 Network Share Discovery” (Ndm448 list) and description: “full file encryption across local and accessible network drives”.
572 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Referenced only as prior context for abuse of the IObit Unlocker driver in separate ransomware intrusions.
Ransomware family mentioned as using NirSoft tools and PsExec; exposed RDP with weak credentials is cited as an access path for Makop.
Ransomware family cited as using Process Hacker to support attack activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.