MegaCortex is a Windows enterprise-targeted ransomware family active from 2019 and associated with organized ransomware operations that also used LockerGoga and Nefilim. It encrypts victim files for extortion and has targeted organizations in Europe and North America across multiple industries. Early activity generally involved manual deployment after compromise of a corporate network; operators deployed it through Active Directory infrastructure or post-exploitation tooling after access was established, including access facilitated by malware such as Emotet. Later variants automated execution, anti-analysis measures, and the termination of security products and services, enabling broader deployment.
MegaCortex variants can remove shadow copies, wipe free space, terminate processes and services that could impede encryption, alter the logged-on Windows account password, and configure a pre-logon message to communicate the compromise when users can no longer sign in. The ransomware creates ransom instructions and has threatened public release of victim data, although data theft by the malware itself has not been conclusively established. It has also been observed using Windows process-manipulation APIs and loading a helper component into a newly created legitimate Windows process. Criminal operations associated with MegaCortex conducted network reconnaissance, lateral movement, and prolonged post-compromise access before ransomware deployment. Law-enforcement investigations have linked MegaCortex activity to large-scale attacks against corporations and critical infrastructure worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The court found the unnamed Ukrainian man to be the lead developer of the LockerGoga, MegaCortex, and Nefilim ransomware families.
Les attaques ont utilisé trois familles de ransomware : LockerGoga, MegaCortex, Nefilim.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
La section « TTPs et IOCs détectés » associe explicitement T1078 — Valid Accounts aux attaques attribuées à Oleksandr Ieremenko.
La section « TTPs et IOCs détectés » associe explicitement T1078 — Valid Accounts aux attaques attribuées à Oleksandr Ieremenko.
APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.
APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.
La section « TTPs et IOCs détectés » associe explicitement T1078 — Valid Accounts aux attaques attribuées à Oleksandr Ieremenko.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The response can be a simple acknowledgment or a longer set of instructions, a module or executable... In many cases the C2 server response only contains an updated version of the binary... If the victim is infected with the latest version of Emotet... the latest modules are downloaded.
Le suspect est présenté comme le principal développeur des rançongiciels Lockergoga, Megacortex et Nefilim; Stadler Rail a été sommée de payer une rançon en bitcoin.
TTPs et IOCs détectés # TTP # T1486 — Data Encrypted for Impact (Impact) T1489 — Service Stop (Impact)
These CMD files will execute a variety of commands that removes shadow volume copies...
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
73 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family allegedly developed by the convicted individual and used in worldwide corporate extortion attacks.
Ransomware family mentioned only in passing in relation to an unrelated Swiss criminal sentence.
Ransomware allegedly developed by the convicted suspect and identified as one of the ransomware families involved in attacks against organizations including Spie and Altran in January 2019.
Ransomware family that the convicted developer was found to have developed; the article does not specify its technical functionality beyond ransomware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.