MegaCortex Ransomware
First observed in early 2019, MegaCortex is a ransomware tool targeted at organisations throughout Western Europe and the USA.
Summary
First observed in early 2019, MegaCortex is a ransomware tool targeted at organisations throughout Western Europe and the USA.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, MegaCortex appears to be delivered via previously compromised domain controllers within a target organisation's network, although there are unconfirmed reports indicating it may also be delivered directly to target systems. Once present on the network, MegaCortex's operators execute a PowerShell-based Cobalt Strike script to open a Meterpreter remote shell on the compromised domain controller. They will then use this shell to invoke the Windows Management Interface console in order to download a fake PsExec file containing MegaCortex, from which it can the be served to devices connecting to the domain controller.
Once installed, MegaCortex will terminate or disable over 300 processes and services before attempting to encrypt all reachable files using an AES-256 algorithm, the key for which is then encrypted using RSA-4096..
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:44 pm