Maktub

First seen
2016-03-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 12:54:35

Context

According to PCrisk, Maktub is ransomware distributed via zipped Word documents. Once the file is extracted and opened, Maktub infiltrates the system and encrypts files stored on the victim's computer. Maktub ransomware adds a .NORV, .gyul (or other random) extension to each file encrypted, thus, making it straightforward to determine which files are encrypted.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Maktub_Auto (yara-rule)

Reports & references

  • intezer.com — Iron Cybercrime Group Under The Scope 2 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Maktub (report)
  • blog.malwarebytes.com — Maktub Locker Beautiful And Dangerous (report)
  • bartblaze.blogspot.de — Maktub Ransomware Possibly Rebranded As (report)

External references