MegaCortex
MITRE ATT&CK: S0576 View on attack.mitre.org
Aliases: MegaCortex
- First seen
- 2019-05-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-02-05 03:48:41
- Profile updated
- 2026-07-07 13:04:26
Targeted industries: manufacturing energy-and-utilities
Context
MegaCortex is ransomware that first appeared in May 2019. MegaCortex has mainly targeted industrial organizations.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to MegaCortex (S0576). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | SecuriteInfo.com.Riskware.00584baa1.7035.19406 | 2026-02-05 | 2 |
Detection coverage
- 3 YARA rules
- 407 Sigma rules
Malware & tools used
- Disable or Modify Tools (attack-pattern)
- Rundll32 (attack-pattern)
- System Checks (attack-pattern)
- Code Signing Certificates (attack-pattern)
- Account Access Removal (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Service Stop (attack-pattern)
- Modify Registry (attack-pattern)
- Disk Content Wipe (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Native API (attack-pattern)
- Access Token Manipulation (attack-pattern)
Detection rules
- TRELLIX_ARC_Megacortex_Signed (yara-rule)
- CAPE_Megacortex (yara-rule)
- MALPEDIA_Win_Megacortex_Auto (yara-rule)
Related threat objects
- LockerGoga (malware)
Reports & references
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
- Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
- zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
- McAfee — Csi Evidence Indicators For Targeted Ransomware Attacks Part Ii (report)
- ransomlook.io — Megacortex (report)
- ptsecurity.com — Incident Response Polar Ransomware Apt27 (report)
- europol.europa.eu — 12 Targeted For Involvement In Ransomware Attacks Against Critical Infrastructure (report)
- npu.gov.ua — Kiberpolicziya Vikrila Transnaczionalne Zlochinne Ugrupovannya U Nanesenni Inozemnim Kompaniyam 120 Miljoniv Dolariv Zbitkiv (report)
- bleepingcomputer.com — Fbi Issues Alert For Lockergoga And Megacortex Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Megacortex (report)
- blog.malwarebytes.com — Ransom Megacortex (report)
- bleepingcomputer.com — Bitdefender Releases Free Megacortex Ransomware Decryptor (report)
- bleepingcomputer.com — Elusive Megacortex Ransomware Found Here Is What We Know (report)
- computing.co.uk — Warning Over Lockergoga And Megacortex Ransomware Attacks Targeting Private Industry In Western Countries (report)
- news.sophos.com — Megacortex Deconstructed Mysteries Mount As Analysis Continues (report)
- Trend Micro — Megacortex Ransomware Spotted Attacking Enterprise Networks (report)
- news.sophos.com — Megacortex Ransomware Wants To Be The One (report)
- threatpost.com — 146933 (report)
- bleepingcomputer.com — New Megacortex Ransomware Changes Windows Passwords Threatens To Publish Data (report)
- Mandiant — Ransomware Against Machine Learning To Disrupt Industrial Production (report)
- MITRE ATT&CK — S0576 (report)
External references
- mitre-attack — S0576
- FireEye Financial Actors Moving into OT
- IBM MegaCortex
- FireEye Ransomware Disrupt Industrial Production
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy