MegaCortex ransomware was reworked from a manually deployed, enterprise-focused threat into a variant better suited for broader distribution, according to researchers. Accenture iDefense reported that MegaCortex v2 hard-coded the installation password into the binary and enabled self-execution, removing steps previously handled by an operator. The malware also added anti-analysis features and automated the stopping or killing of security products and services, raising concerns that it could be spread more widely through email campaigns or dropped as a secondary payload by other malware families. Earlier campaigns had already hit enterprises in Europe and North America, with reported ransom demands ranging from 2 to 600 Bitcoin.
A later MegaCortex variant became more aggressive after execution, encrypting files with the .m3g4c0rtx extension, dropping the ransom note !-!_README_!-!.rtf, and changing victims’ Windows account passwords. Researchers said MegaCortex was typically deployed after attackers gained network access through trojans such as Emotet, then moved through environments using Active Directory controllers or post-exploitation tools. The updated ransom note also threatened to publish stolen data if victims refused to pay, signaling an early shift toward double-extortion tactics, while the malware launcher was found signed with a Sectigo certificate issued to MURSA PTY LTD that was later revoked.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Sectigo told BleepingComputer it revoked the abused code-signing certificate issued to MURSA PTY LTD after it was used to sign the MegaCortex launcher sample. The revocation occurred at 4:20 PM ET on November 5, 2019.
Analysis of the newly discovered variant found it appends the .m3g4c0rtx extension, sets a pre-login legal notice, changes the victim's Windows account password with the net user command, and drops a ransom note threatening to publish stolen data. The report noted that actual data theft was not confirmed.
On November 5, 2019, MalwareHunterTeam discovered a new MegaCortex sample that Vitali Kremez reverse engineered. Analysis showed a 2019 variant with more aggressive behavior beyond encryption.
Accenture iDefense reported that a second MegaCortex variant removed the attacker-supplied installation password, hard-coded it in the binary, and enabled self-execution. The new version also automated disabling security products and added anti-analysis features, potentially allowing wider distribution by affiliates or third parties.
Before its later redesigns, MegaCortex was used in manual, post-network-exploitation campaigns against carefully selected enterprise targets in Europe and North America. Operators reportedly demanded between 2 and 600 Bitcoins from victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.