ATT&CKReferencesIBM MegaCortex

IBM MegaCortex

Del Fierro, C. Kessem, L.. (2020, January 8). From Mega to Giga: Cross-Version Comparison of Top MegaCortex Modifications. Retrieved February 15, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
MalwareMegaCortex

MegaCortex loads injecthelper.dll into a newly created rundll32.exe process.

T1059.003
Windows Command Shell
MalwareMegaCortex

MegaCortex has used .cmd scripts on the victim's system.

T1083
File and Directory Discovery
MalwareMegaCortex

MegaCortex can parse the available drives and directories to determine which files to encrypt.

T1106
Native API
MalwareMegaCortex

After escalating privileges, MegaCortex calls TerminateProcess(), CreateRemoteThread, and other Win32 APIs.

T1112
Modify Registry
MalwareMegaCortex

MegaCortex has added entries to the Registry for ransom contact information.

T1134
Access Token Manipulation
MalwareMegaCortex

MegaCortex can enable SeDebugPrivilege and adjust token privileges.

T1140
Deobfuscate/Decode Files or Information
MalwareMegaCortex

MegaCortex has used a Base64 key to decode its components.

T1218.011
Rundll32
MalwareMegaCortex

MegaCortex has used rundll32.exe to load a DLL for file encryption.

T1486
Data Encrypted for Impact
MalwareMegaCortex

MegaCortex has used the open-source library, Mbed Crypto, and generated AES keys to carry out the file encryption process.

T1489
Service Stop
MalwareMegaCortex

MegaCortex can stop and disable services on the system.

T1490
Inhibit System Recovery
MalwareMegaCortex

MegaCortex has deleted volume shadow copies using vssadmin.exe.

T1497.001
System Checks
MalwareMegaCortex

MegaCortex has checked the number of CPUs in the system to avoid being run in a sandbox or emulator.

T1531
Account Access Removal
MalwareMegaCortex

MegaCortex has changed user account passwords and logged users off the system.

T1561.001
Disk Content Wipe
MalwareMegaCortex

MegaCortex can wipe deleted data from all drives using cipher.exe.

T1588.003
Code Signing Certificates
MalwareMegaCortex

MegaCortex has used code signing certificates issued to fake companies to bypass security controls.

T1685
Disable or Modify Tools
MalwareMegaCortex

MegaCortex was used to kill endpoint security processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.