Makop ransomware: GuLoader and privilege escalation in attacks against Indian businesses
Makop, a ransomware strain derived from Phobos, is targeting Indian businesses through exposed RDP systems. The attackers employ a diverse toolkit including network scanners, privilege escalation exploits, and AV killers. They have integrated GuLoader, a downloader trojan, to deliver secondary payloads and bypass security measures. The attack chain typically involves RDP exploitation, followed by network scanning, lateral movement, and privilege escalation before encryption. The majority of attacks (55%) target organizations in India. Makop operators use off-the-shelf tools and multiple local privilege escalation vulnerabilities to maximize their impact. The inclusion of a tailored Quick Heal AV uninstaller indicates adaptation to specific regional targets.
Pulse ID: 693857c7124842e89ec8bfed
Pulse Link: https://otx.alienvault.com/pulse/693857c7124842e89ec8bfed
Pulse Author: AlienVault
Created: 2025-12-09 17:09:27
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #Encryption #GULOADER #India #InfoSec #OTX #OpenThreatExchange #Phobos #RAT #RDP #RansomWare #Trojan #bot #AlienVault


















