Makop

Malware

⚠️ Overview

Makop is a ransomware family first identified in early 2020, operated as a Ransomware-as-a-Service (RaaS) by an unnamed Russian-speaking threat actor. It is classified as a crypto-ransomware that encrypts files and demands payment in Bitcoin for decryption. Initial discovery was reported by malware analysts at BleepingComputer and later documented by Fortinet and Trend Micro.

🔧 Technical Capabilities

Makop uses a custom encryptor that appends the extension .makop (or variants such as .makop2) to affected files. It propagates primarily through phishing emails with malicious attachments, exploit kits targeting vulnerable RDP services (CVE-2019-0708 BlueKeep), and lateral movement using PsExec or WMI. The malware establishes persistence via registry run keys and scheduled tasks. Evasion techniques include process hollowing, API unhooking, and disabling Windows Defender through PowerShell commands. C2 communication is over HTTP/HTTPS with a custom binary protocol, sometimes using Tor for anonymity. The ransomware deletes shadow copies using vssadmin.exe and disables recovery options.

📜 History & Notable Incidents

First publicly documented in February 2020 by BleepingComputer, Makop has been used in multiple campaigns targeting healthcare, education, and small-to-medium businesses (SMBs) globally. In early 2021, a high-profile incident affected a US healthcare network, disrupting patient records. No specific CVEs are exclusively tied to Makop; it leverages known vulnerabilities such as CVE-2020-1472 (Zerologon) and CVE-2021-34527 (PrintNightmare) for initial access in later variants. Law enforcement actions have not directly disrupted the group, but decryption tools from Avast and Emsisoft have been released for certain older versions.

🔍 Detection Indicators

Known file hashes include SHA256: a3f7b2c1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (example from VT, not universal). Behavioral indicators include immediate deletion of Volume Shadow Copies via vssadmin delete shadows /all /quiet, creation of ransom notes named README-MAKOP.txt, and network connections to IPs under ASN 51167 (Contabo) or 162.247.74.0/24. Registry keys such as HKCUSoftwareMicrosoftWindowsCurrentVersionRunMakop are used. Mutex name GlobalMakopMutex has been observed in samples. User-Agent strings vary but often mimic outdated browsers like Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0.

☠️ Risk & Impact

Makop causes irreversible file encryption, leading to data loss if backups are unavailable. Financial losses per incident range from thousands to hundreds of thousands of dollars in ransom demands, with additional costs from downtime and recovery. The healthcare and education sectors are frequently targeted due to high dependency on data availability. Data exfiltration is not a standard feature, but some variants have been observed with information-stealing modules.

🛡️ Mitigation

Mitigation includes applying security patches for RDP vulnerabilities (e.g., CVE-2019-0708), enforcing multi-factor authentication, restricting PowerShell execution policy, and maintaining offline backups. Detection rules such as SIGMA rules for shadow copy deletion and YARA signatures for Makop binaries are available from open-source repositories like Florian Roth's GitHub. Endpoint detection and response (EDR) tools like Microsoft Defender for Endpoint can block known behavior.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.