ATT&CKSoftwareMegaCortex

MegaCortex

S0576

Malware.View on attack.mitre.org

About this malware

MegaCortex is ransomware that first appeared in May 2019. MegaCortex has mainly targeted industrial organizations.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1055.001
Dynamic-link Library Injection

MegaCortex loads injecthelper.dll into a newly created rundll32.exe process.

T1059.003
Windows Command Shell

MegaCortex has used .cmd scripts on the victim's system.

T1083
File and Directory Discovery

MegaCortex can parse the available drives and directories to determine which files to encrypt.

T1106
Native API

After escalating privileges, MegaCortex calls TerminateProcess(), CreateRemoteThread, and other Win32 APIs.

T1112
Modify Registry

MegaCortex has added entries to the Registry for ransom contact information.

T1134
Access Token Manipulation

MegaCortex can enable SeDebugPrivilege and adjust token privileges.

T1140
Deobfuscate/Decode Files or Information

MegaCortex has used a Base64 key to decode its components.

T1218.011
Rundll32

MegaCortex has used rundll32.exe to load a DLL for file encryption.

T1486
Data Encrypted for Impact

MegaCortex has used the open-source library, Mbed Crypto, and generated AES keys to carry out the file encryption process.

T1489
Service Stop

MegaCortex can stop and disable services on the system.

T1490
Inhibit System Recovery

MegaCortex has deleted volume shadow copies using vssadmin.exe.

T1497.001
System Checks

MegaCortex has checked the number of CPUs in the system to avoid being run in a sandbox or emulator.

T1531
Account Access Removal

MegaCortex has changed user account passwords and logged users off the system.

T1561.001
Disk Content Wipe

MegaCortex can wipe deleted data from all drives using cipher.exe.

T1588.003
Code Signing Certificates

MegaCortex has used code signing certificates issued to fake companies to bypass security controls.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. FireEye Financial Actors Moving into OT Open source
    Brubaker, N. Zafra, D. K. Lunden, K. Proska, K. Hildebrandt, C.. (2020, July 15). Financially Motivated Actors Are Expanding Access Into OT: Analysis of Kill Lists That Include OT Processes Used With Seven Malware Families. Retrieved February 15, 2021.
  2. FireEye Ransomware Disrupt Industrial Production Open source
    Zafra, D. Lunden, K. Brubaker, N. Kennelly, J.. (2020, February 24). Ransomware Against the Machine: How Adversaries are Learning to Disrupt Industrial Production by Targeting IT and OT. Retrieved February 9, 2021.
  3. IBM MegaCortex Open source
    Del Fierro, C. Kessem, L.. (2020, January 8). From Mega to Giga: Cross-Version Comparison of Top MegaCortex Modifications. Retrieved February 15, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.