logo

Makop Ransomware Exploits RDP Systems with AV Killer and Other Exploits

ID: 749af8dc-eb57-510c-b6c4-06ebe3c0aa36

STIX ID: report--749af8dc-eb57-510c-b6c4-06ebe3c0aa36

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Acronis and related analysis detail active Makop ransomware operations that primarily gain access via RDP brute-force, deploy network reconnaissance and credential-dumping tools, and escalate privileges using a catalogue of local-exploit CVEs and Bring-Your-Own-Vulnerable-Driver techniques (e.g., ThrottleStop.sys, hlpdrv.sys) to disable EDR/AV and deploy encryption payloads; the campaign has a strong focus on India but affects other regions and now includes GuLoader for secondary payload delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.