Makop Ransomware Exploits RDP Systems with AV Killer and Other Exploits
ID: 749af8dc-eb57-510c-b6c4-06ebe3c0aa36
STIX ID: report--749af8dc-eb57-510c-b6c4-06ebe3c0aa36
Feed Name: cybersecurityNews.com
Acronis and related analysis detail active Makop ransomware operations that primarily gain access via RDP brute-force, deploy network reconnaissance and credential-dumping tools, and escalate privileges using a catalogue of local-exploit CVEs and Bring-Your-Own-Vulnerable-Driver techniques (e.g., ThrottleStop.sys, hlpdrv.sys) to disable EDR/AV and deploy encryption payloads; the campaign has a strong focus on India but affects other regions and now includes GuLoader for secondary payload delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
