The research highlights the evolution of ransomware techniques and the risks associated with unprotected RDP
Acronis, global leader in the cybersecurity and in the data protection, announces that the Acronis Threat Research Unit (TRU) has conducted a new analysis on the most recent campaigns of the Makop ransomware, a threat active since 2020 and attributable to the family Phobos. The research highlights how the group continues to exploit exposed and inadequately protected RDP systems, while integrating new tools and techniques to increase the effectiveness of attacks and bypass security measures.
The campaigns observed demonstrate a deliberately low-complexity methodology, based on initial login via weak or reused RDP credentials, often obtained through brute force attacks or password spraying. Once access is gained, attackers proceed with reconnaissance and lateral movement within the network, using commonly available tools for system scanning, credential extraction, and privilege escalation.
An important element that emerged from the analysis concerns the widespread use of local privilege escalation vulnerabilities on Windows systems, including known and documented flaws over the years, exploited thanks to the availability of public and reliable proof-of-concepts. This approach allows Makop operators to quickly gain system privileges, necessary to disable security controls and maximize the impact of the attack.
Alongside these established techniques, TRU researchers observed the introduction of Guloader, a loader-type malware used to deliver additional payloads. This is the first documented case in which Makop uses a loader to distribute ransomware, marking an evolution in the group's tactics and an alignment with the operating methods already adopted by other ransomware families. The use of Guloader allows for greater flexibility in the infection chain and helps evade detection systems.
Evasive defense activities represent another central aspect of the analyzed campaigns. Several tools aimed at disabling or removing security solutions have been identified, including vulnerable drivers exploited using BYOVD (Bring Your Own Vulnerable Driver) techniques and legitimate software abused to terminate processes or uninstall endpoint protections. In some cases, the toolkit is adapted to the geographical context of the victims, as demonstrated by the use of specific tools for the removal of antivirus solutions widespread in certain areas.
Geographically, more than half of the attacks observed affected organizations based in India, followed by cases detected in Brazil, Germany and other countries. According to TRU's analysis, this deployment reflects an opportunistic approach, oriented towards contexts characterized by deficient security configurations, which reduce the effort required to compromise systems.
Analysis of Makop campaigns confirms how seemingly trivial access points, such as RDP services exposed without adequate protection measures, can result in serious incidents. The systematic use of common tools, known vulnerabilities and proven techniques demonstrates how even low-sophistication attacks can be highly effective in the absence of adequate controls.
During the analysis activities, the components used in the Makop campaigns were detected and blocked by Acronis EDR/XDR solutions, capable of intercepting both the ransomware and the different phases of the attack chain, including evasive defense activities, the abuse of vulnerable drivers and the execution of malware loaders such as Guloader. The approach based on behavioral analysis and event correlation allows for the timely identification of these threats, even when they use legitimate tools or already known techniques.
Finally, the study reiterates the importance of adopting basic but rigorous security measures, including the use of strong credentials, enabling multi-factor authentication for remote access and timely management of security updates, essential elements for reducing exposure to ransomware risk and other advanced threats.






