MegaCortex is a financially motivated ransomware operation active alongside the LockerGoga and Nefilim ransomware schemes. U.S. prosecutors have alleged that Ukrainian national Volodymyr Viktorovich Tymoshchuk, also known as deadforz, Boba, msfv, and farnetwork, administered all three operations. A Swiss court convicted a Ukrainian developer for creating code used by MegaCortex, LockerGoga, and Nefilim, while finding that developer was not the operations' mastermind. MegaCortex and LockerGoga compromised corporate networks between July 2019 and June 2020, affecting more than 250 U.S. companies and hundreds of organizations globally. The operation deployed victim-specific ransomware executables and provided decryption tools following ransom payment. MegaCortex has used Qakbot access obtained through the Qakbot ecosystem and has deleted Volume Shadow Copies to impede recovery. Decryption keys for MegaCortex were released through the No More Ransom project in 2022.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation for which the convicted developer was found to have developed code; US prosecutors allege Volodymyr Tymoshchuk was the mastermind of the operation.
MegaCortex is a ransomware operation managed by individuals such as Tymoshchuk, targeting organizations for financial gain.
MegaCortex is associated with ransomware attacks that breached hundreds of companies worldwide, resulting in millions of dollars in damages.
MegaCortex is a ransomware strain associated with actors linked to Nefilim, used in corporate extortion campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.