MegaCortex

MITRE ATT&CK: S0576 View on attack.mitre.org

Aliases: MegaCortex

First seen
2019-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-02-05 03:48:41
Profile updated
2026-07-07 13:04:26

Targeted industries: manufacturing energy-and-utilities

Context

MegaCortex is ransomware that first appeared in May 2019. MegaCortex has mainly targeted industrial organizations.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to MegaCortex (S0576). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample SecuriteInfo.com.Riskware.00584baa1.7035.19406 2026-02-05 2

Detection coverage

  • 3 YARA rules
  • 407 Sigma rules

Malware & tools used

  • Disable or Modify Tools (attack-pattern)
  • Rundll32 (attack-pattern)
  • System Checks (attack-pattern)
  • Code Signing Certificates (attack-pattern)
  • Account Access Removal (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Service Stop (attack-pattern)
  • Modify Registry (attack-pattern)
  • Disk Content Wipe (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Native API (attack-pattern)
  • Access Token Manipulation (attack-pattern)

Detection rules

  • TRELLIX_ARC_Megacortex_Signed (yara-rule)
  • CAPE_Megacortex (yara-rule)
  • MALPEDIA_Win_Megacortex_Auto (yara-rule)

Related threat objects

Reports & references

  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
  • McAfee — Csi Evidence Indicators For Targeted Ransomware Attacks Part Ii (report)
  • ransomlook.io — Megacortex (report)
  • ptsecurity.com — Incident Response Polar Ransomware Apt27 (report)
  • europol.europa.eu — 12 Targeted For Involvement In Ransomware Attacks Against Critical Infrastructure (report)
  • npu.gov.ua — Kiberpolicziya Vikrila Transnaczionalne Zlochinne Ugrupovannya U Nanesenni Inozemnim Kompaniyam 120 Miljoniv Dolariv Zbitkiv (report)
  • bleepingcomputer.com — Fbi Issues Alert For Lockergoga And Megacortex Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Megacortex (report)
  • blog.malwarebytes.com — Ransom Megacortex (report)
  • bleepingcomputer.com — Bitdefender Releases Free Megacortex Ransomware Decryptor (report)
  • bleepingcomputer.com — Elusive Megacortex Ransomware Found Here Is What We Know (report)
  • computing.co.uk — Warning Over Lockergoga And Megacortex Ransomware Attacks Targeting Private Industry In Western Countries (report)
  • news.sophos.com — Megacortex Deconstructed Mysteries Mount As Analysis Continues (report)
  • Trend Micro — Megacortex Ransomware Spotted Attacking Enterprise Networks (report)
  • news.sophos.com — Megacortex Ransomware Wants To Be The One (report)
  • threatpost.com — 146933 (report)
  • bleepingcomputer.com — New Megacortex Ransomware Changes Windows Passwords Threatens To Publish Data (report)
  • Mandiant — Ransomware Against Machine Learning To Disrupt Industrial Production (report)
  • MITRE ATT&CK — S0576 (report)

External references