MEGACORTEX
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
The MegaCortex ransomware first appeared in January 2019 with few interesting attributes, including the use of a signed executable as part of the payload. It also appeared to offer security consulting services from the malware author.
On May 1, 2019, a reported spike in volume of MegaCortex ransomware was reported. It seemed to be aimed at enterprise networks in US, Canada, France, Netherlands, Ireland and Italy. The ransomware used both automated and manual components to infect as may victims as possible.
The MegaCortex ransomware appears to affect corporations rather than individual users based on reports. It also is possibly using networks that have already been compromised in a previous attack using Emotet and Qakbot malware.
It is capable of the following:
- Information Theft
- File Encryption
- Disabling usage capability
MegaCortex ransomware typically has the following infection chain: