Makop ransomware: GuLoader and privilege escalation in attacks against Indian businesses
ID: 26460e98-d057-5181-8a00-941af71a3f51
STIX ID: report--26460e98-d057-5181-8a00-941af71a3f51
Feed Name: TRU Security by Acronis
Threat Score
**Makop ransomware campaigns**: Acronis TRU analysis shows Makop (Phobos variant) continues to target exposed RDP with brute-force access, stages off‑the‑shelf network scanners, credential dumpers and numerous local privilege escalation exploits, and increasingly uses loaders like GuLoader to deploy payloads; observed tooling, regionally tailored AV uninstallers (notably Quick Heal), and multiple CVEs exploited are documented along with extensive IOCs and detection notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
