Skip to content

Makop

Makop is a human-operated ransomware family active since around 2020 and commonly assessed as a Phobos-derived ransomware-as-a-service variant.

Profile source: Mallory opens in a new tab

Makop

Family profile

Makop is a human-operated ransomware family active since around 2020 and commonly assessed as a Phobos-derived ransomware-as-a-service variant. It primarily targets Windows environments and has been observed compromising organizations through exposed Remote Desktop Protocol services, including brute-force and dictionary attacks against weak credentials, as well as through spearphishing campaigns delivering malicious attachments. Makop activity has affected organizations in multiple regions, including South Korea, India, Brazil, Germany, Europe, and Italy, and has also been reported against critical infrastructure such as water and wastewater entities.

Makop intrusions typically involve substantial hands-on-keyboard post-compromise activity before encryption. Operators stage a toolkit of legitimate and custom utilities for network discovery, credential access, lateral movement, privilege escalation, persistence, and defense evasion. Observed tooling includes scanners and administrative utilities, credential theft tools such as Mimikatz, LaZagne, and NirSoft utilities, remote execution via PsExec, and process-termination or deletion tools such as Process Hacker and IOBit Unlocker. Makop operators have also used custom .NET tools including ARestore, which generates and tests local Windows credential combinations, and PuffedUp, which establishes persistence. Recent reporting also describes use of GuLoader to deliver additional payloads, including Makop, marking an evolution from earlier direct deployment patterns.

Defense evasion and privilege escalation are prominent in Makop operations. Operators have disabled Microsoft Defender, attempted to uninstall security products, and abused bring-your-own-vulnerable-driver techniques to gain kernel-level capability and interfere with endpoint defenses. Multiple Windows local privilege escalation exploits have been associated with Makop intrusions. Recovery inhibition behavior includes deletion of shadow copies and modification of boot settings prior to file encryption. Some variants also add persistence mechanisms before rebooting systems.

Makop has been linked to double-extortion style pressure in some family variants, with ransom notes claiming data theft prior to encryption. Related variants such as Ndm448 encrypt local and accessible network drives, traverse user and system directories extensively, and drop ransom notes while threatening disclosure of stolen data. Across reporting, Makop appears opportunistic rather than narrowly sector-specific, with operators reusing a stable mix of commodity tools and custom malware over several years.

Capabilities

  • Brute Force
  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 16, 2026
Last activity
Sep 16, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Makop

Insights from a recent intrusion authored by Makop ransomware operators show persistence capability through dedicated .NET tools. Makop toolkit includes both off-the-shelf tools and custom-developed ones, including tools from the Chinese underground ecosystem.

Exploited software

Vulnerabilities linked to Makop

11 CVEs

MITRE ATT&CK

Makop in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.