PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

The MegaCortex ransomware first appeared in January 2019 with few interesting attributes, including the use of a signed executable as part of the payload. It also appeared to offer security consulting services from the malware author.

On May 1, 2019, a reported spike in volume of MegaCortex ransomware was reported. It seemed to be aimed at enterprise networks in US, Canada, France, Netherlands, Ireland and Italy. The ransomware used both automated and manual components to infect as may victims as possible.

The MegaCortex ransomware appears to affect corporations rather than individual users based on reports. It also is possibly using networks that have already been compromised in a previous attack using Emotet and Qakbot malware.

It is capable of the following:

  • Information Theft

  • File Encryption

  • Disabling usage capability

MegaCortex ransomware typically has the following infection chain: