Malware.View on attack.mitre.org
MegaCortex is ransomware that first appeared in May 2019. MegaCortex has mainly targeted industrial organizations.
| Technique | Procedure example |
|---|---|
| T1055.001 Dynamic-link Library Injection |
MegaCortex loads |
| T1059.003 Windows Command Shell |
MegaCortex has used |
| T1083 File and Directory Discovery |
MegaCortex can parse the available drives and directories to determine which files to encrypt. |
| T1106 Native API |
After escalating privileges, MegaCortex calls |
| T1112 Modify Registry |
MegaCortex has added entries to the Registry for ransom contact information. |
| T1134 Access Token Manipulation |
MegaCortex can enable |
| T1140 Deobfuscate/Decode Files or Information |
MegaCortex has used a Base64 key to decode its components. |
| T1218.011 Rundll32 |
MegaCortex has used |
| T1486 Data Encrypted for Impact |
MegaCortex has used the open-source library, Mbed Crypto, and generated AES keys to carry out the file encryption process. |
| T1489 Service Stop |
MegaCortex can stop and disable services on the system. |
| T1490 Inhibit System Recovery |
MegaCortex has deleted volume shadow copies using |
| T1497.001 System Checks |
MegaCortex has checked the number of CPUs in the system to avoid being run in a sandbox or emulator. |
| T1531 Account Access Removal |
MegaCortex has changed user account passwords and logged users off the system. |
| T1561.001 Disk Content Wipe |
MegaCortex can wipe deleted data from all drives using |
| T1588.003 Code Signing Certificates |
MegaCortex has used code signing certificates issued to fake companies to bypass security controls. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.