MegaCortex, also tracked as megacortex_actors, is a financially motivated ransomware operation targeting corporate networks. Its attacks encrypt victim data and demand ransom payments in exchange for decryption tools. Victim environments associated with the LockerGoga and MegaCortex operations include companies in the United States and elsewhere, including healthcare institutions and large industrial enterprises. MegaCortex operators have used QakBot, also known as QBot, to obtain initial access to corporate networks and deliver ransomware. MegaCortex deletes Windows Volume Shadow Copies using the native Volume Shadow Copy administration utility, inhibiting recovery of encrypted data. Ransomware executables have been customized for individual victims, with unique decryption keys and decryption tools supplied following payment. MegaCortex shares development personnel with the LockerGoga and Nefilim ransomware operations. A Ukrainian developer was convicted in Switzerland for creating code used by all three operations; the court distinguished his development role from leadership of the operations. Decryption keys for MegaCortex and LockerGoga were released through the No More Ransom project in September 2022, enabling affected victims to recover data without paying ransoms.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation for which the convicted developer was found to have developed code; US prosecutors allege Volodymyr Tymoshchuk was the mastermind of the operation.
MegaCortex is a ransomware operation managed by individuals such as Tymoshchuk, targeting organizations for financial gain.
MegaCortex is associated with ransomware attacks that breached hundreds of companies worldwide, resulting in millions of dollars in damages.
MegaCortex is a ransomware strain associated with actors linked to Nefilim, used in corporate extortion campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.