Makop Ransomware Targets RDP Systems Using AV Killer and Additional Exploits
The Makop ransomware, originating from the Phobos strain, continues to be a significant threat by targeting exposed Remote Desktop Protocol (RDP) systems. Recent updates have introduced new components such as antivirus-killer modules and advanced…
The Makop ransomware, originating from the Phobos strain, continues to be a significant threat by targeting exposed Remote Desktop Protocol (RDP) systems. Recent updates have introduced new components such as antivirus-killer modules and advanced privilege-escalation exploits.
According to Acronis TRU researchers, the operators of Makop have enhanced their methodologies with multiple evasion techniques and secondary payload delivery mechanisms.
The attack sequence begins with the exploitation of RDP via brute-force attacks on weak credentials, followed by network reconnaissance, privilege escalation, and encryption. Operators typically abandon attacks when faced with resilient security solutions, indicating a focus on efficiency.
Initial access is primarily gained through public RDP services, exploiting weak or reused credentials via brute-force attacks utilizing tools such as NLBrute, an automation tool for RDP password guessing.
Once inside, attackers use network scanning tools like NetScan and Advanced IP Scanner to identify active hosts for lateral movement.
A notable advancement in Makop's arsenal involves sophisticated evasion tactics. Attackers deploy antivirus killers, including Defender Control and Disable Defender, to disable Microsoft Defender protections.
The Makop ransomware, originating from the Phobos strain, continues to be a significant threat by targeting exposed Remote Desktop Protocol (RDP) systems.
The group employs BYOVD (Bring Your Own Vulnerable Driver) methods, utilizing signed drivers such as ThrottleStop.sys and hlpdrv.sys to gain kernel-level access and disable EDR solutions.
Furthermore, operators use customized uninstallers targeting region-specific security solutions. This includes a Quick Heal AV uninstaller, aligning with data indicating that 55% of Makop attacks target Indian organizations.
Makop's collection of local privilege escalation (LPE) exploits spans from older to recent vulnerabilities, including CVE-2017-0213, CVE-2018-8639, CVE-2021-41379, and CVE-2016-0099. This allows operators to maintain redundancy and effectiveness across different Windows versions.
Credential dumping tools such as Mimikatz, LaZagne, and NetPass are employed to extract plaintext passwords, NTLM hashes, and cached credentials, facilitating lateral movement and expanded access.
Additionally, legitimate applications like Process Hacker and IOBitUnlocker are misused to terminate processes and delete programs.
A significant development is the integration of GuLoader, a downloader trojan traditionally used for delivering malware such as AgentTesla and FormBook. This is the first recorded instance of GuLoader being utilized to distribute Makop ransomware, indicating an evolution in secondary payload delivery mechanisms.
Makop primarily targets organizations in India, with incidents also reported in Brazil, Germany, and other regions. This distribution appears to exploit networks with weak security postures rather than indicating a geographical preference.
Organizations are advised to secure RDP services with strong authentication mechanisms, implement multi-factor authentication, and regularly patch known LPE vulnerabilities. Regular network monitoring, application whitelisting, and behavioral analysis are recommended to detect and prevent exploitation attempts before encryption occurs.
Based on reporting by GBHackers.
