Maktub
- First seen
- 2016-03-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 12:54:35
Context
According to PCrisk, Maktub is ransomware distributed via zipped Word documents. Once the file is extracted and opened, Maktub infiltrates the system and encrypts files stored on the victim's computer. Maktub ransomware adds a .NORV, .gyul (or other random) extension to each file encrypted, thus, making it straightforward to determine which files are encrypted.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Maktub_Auto (yara-rule)
Reports & references
- intezer.com — Iron Cybercrime Group Under The Scope 2 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Maktub (report)
- blog.malwarebytes.com — Maktub Locker Beautiful And Dangerous (report)
- bartblaze.blogspot.de — Maktub Ransomware Possibly Rebranded As (report)