Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Makop Ransomware Targets RDP Systems Using AV Killer and Additional Exploits

The Makop ransomware, originating from the Phobos strain, continues to be a significant threat by targeting exposed Remote Desktop Protocol (RDP) systems. Recent updates have introduced new components such as antivirus-killer modules and advanced…

The Makop ransomware, originating from the Phobos strain, continues to be a significant threat by targeting exposed Remote Desktop Protocol (RDP) systems. Recent updates have introduced new components such as antivirus-killer modules and advanced privilege-escalation exploits.

According to Acronis TRU researchers, the operators of Makop have enhanced their methodologies with multiple evasion techniques and secondary payload delivery mechanisms.

The attack sequence begins with the exploitation of RDP via brute-force attacks on weak credentials, followed by network reconnaissance, privilege escalation, and encryption. Operators typically abandon attacks when faced with resilient security solutions, indicating a focus on efficiency.

Initial access is primarily gained through public RDP services, exploiting weak or reused credentials via brute-force attacks utilizing tools such as NLBrute, an automation tool for RDP password guessing.

Once inside, attackers use network scanning tools like NetScan and Advanced IP Scanner to identify active hosts for lateral movement.

A notable advancement in Makop's arsenal involves sophisticated evasion tactics. Attackers deploy antivirus killers, including Defender Control and Disable Defender, to disable Microsoft Defender protections.

The Makop ransomware, originating from the Phobos strain, continues to be a significant threat by targeting exposed Remote Desktop Protocol (RDP) systems.
Eleanor Tate · Thehackingpost

The group employs BYOVD (Bring Your Own Vulnerable Driver) methods, utilizing signed drivers such as ThrottleStop.sys and hlpdrv.sys to gain kernel-level access and disable EDR solutions.

Furthermore, operators use customized uninstallers targeting region-specific security solutions. This includes a Quick Heal AV uninstaller, aligning with data indicating that 55% of Makop attacks target Indian organizations.

Makop's collection of local privilege escalation (LPE) exploits spans from older to recent vulnerabilities, including CVE-2017-0213, CVE-2018-8639, CVE-2021-41379, and CVE-2016-0099. This allows operators to maintain redundancy and effectiveness across different Windows versions.

Credential dumping tools such as Mimikatz, LaZagne, and NetPass are employed to extract plaintext passwords, NTLM hashes, and cached credentials, facilitating lateral movement and expanded access.

Advertisement

Additionally, legitimate applications like Process Hacker and IOBitUnlocker are misused to terminate processes and delete programs.

A significant development is the integration of GuLoader, a downloader trojan traditionally used for delivering malware such as AgentTesla and FormBook. This is the first recorded instance of GuLoader being utilized to distribute Makop ransomware, indicating an evolution in secondary payload delivery mechanisms.

Makop primarily targets organizations in India, with incidents also reported in Brazil, Germany, and other regions. This distribution appears to exploit networks with weak security postures rather than indicating a geographical preference.

Organizations are advised to secure RDP services with strong authentication mechanisms, implement multi-factor authentication, and regularly patch known LPE vulnerabilities. Regular network monitoring, application whitelisting, and behavioral analysis are recommended to detect and prevent exploitation attempts before encryption occurs.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories