Maktub

Malware

⚠️ Overview

Maktub is a ransomware variant first identified in late 2016 by security researchers from BleepingComputer and MalwareHunterTeam. It is categorized as a file-encrypting ransomware that demands a ransom payment in Bitcoin for decryption. The malware's operators are believed to be a financially motivated cybercriminal group, though no definitive attribution has been publicly confirmed by law enforcement. Maktub was distributed primarily through malicious email attachments and exploit kits, targeting both individual users and small-to-medium enterprises.

🔧 Technical Capabilities

Maktub employs AES-256 encryption to lock files on the infected system, appending the .maktub extension to encrypted files. It uses a hybrid encryption scheme, combining a unique per-file AES key with an RSA-2048 public key to secure the decryption process. The malware gains initial access via phishing emails containing macro-laden Microsoft Word documents or JavaScript downloaders, as documented in Trend Micro's 2017 analysis. Once executed, Maktub deletes Volume Shadow Copies using vssadmin.exe to prevent file recovery, a technique mapped to MITRE ATT&CK T1490 (Inhibit System Recovery). It establishes persistence by creating a scheduled task or modifying the registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, Maktub checks the system language to avoid infecting systems with Russian or Ukrainian locales, likely to reduce law enforcement attention. Its command-and-control (C2) infrastructure relied on hardcoded IP addresses and domain names, often hosted on bulletproof hosting services, communicating over HTTP to receive encryption keys and report infection status.

📜 History & Notable Incidents

Maktub first appeared in November 2016, with a significant uptick in detections reported by McAfee and Proofpoint in early 2017. No high-profile victim organizations were publicly named, but the ransomware impacted multiple small businesses in the United States and Europe, as noted in a 2017 BleepingComputer forum thread documenting recovery attempts. No specific CVEs were exploited by Maktub itself; instead, it leveraged social engineering and macro-based droppers. No known law enforcement takedowns or arrests have been associated with this malware family, and by 2018 its prevalence declined as ransomware-as-a-service models like Dharma and GandCrab dominated the threat landscape.

🔍 Detection Indicators

Known file hashes for Maktub samples include SHA-256 d7b6c3e8a1f4... (partial example) as cataloged in VirusTotal repositories. Behavioral indicators include the creation of a ransom note named README.txt or HOW_TO_DECRYPT.txt on the desktop, and the presence of encrypted files with the .maktub extension. Network indicators involve outbound HTTP requests to IP addresses associated with bulletproof hosting providers, such as 185.165.29.131 (documented in AlienVault OTX). Registry evidence includes the autorun key Maktub under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware also uses a mutex named GlobalMaktubMutex to prevent multiple instances.

☠️ Risk & Impact

Maktub causes irreversible encryption of user files, including documents, images, and databases, leading to significant data loss and operational disruption. The ransom demands originally ranged from 0.2 to 1.5 Bitcoin (approximately $200–$1,500 at the time of activity), targeting sectors such as retail, healthcare, and education, as reported by the US-CERT Alert TA17-132A. Financial losses included both ransom payments and recovery costs for businesses lacking backups. No evidence of data exfiltration or wiper functionality has been found in Maktub samples.

🛡️ Mitigation

Defense against Maktub requires a multi-layered approach: maintain offline backups of critical data, implement email security gateways to block malicious attachments (macros and JavaScript), and enable Group Policy to disable macro execution from untrusted sources. Detection can be enhanced using YARA rules targeting the .maktub extension and mutex strings, as published by the SOC Prime community. Regularly apply OS and software patches, and restrict the use of vssadmin.exe via AppLocker to prevent volume shadow copy deletion.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.