logo

Makop ransomware: GuLoader and privilege escalation in attacks against Indian businesses

ID: 26460e98-d057-5181-8a00-941af71a3f51

STIX ID: report--26460e98-d057-5181-8a00-941af71a3f51

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2025-12-08

Date Updated: 2026-07-24

...
...

**Makop ransomware campaigns**: Acronis TRU analysis shows Makop (Phobos variant) continues to target exposed RDP with brute-force access, stages off‑the‑shelf network scanners, credential dumpers and numerous local privilege escalation exploits, and increasingly uses loaders like GuLoader to deploy payloads; observed tooling, regionally tailored AV uninstallers (notably Quick Heal), and multiple CVEs exploited are documented along with extensive IOCs and detection notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.