MegaCortex is Windows ransomware first discovered in May 2019 and designed for targeted attacks against enterprise networks. Financially motivated operators deploy it after obtaining access to corporate environments, including through QakBot infections and remote execution with PsExec. Its campaigns have targeted financially capable companies in Western Europe and North America. A Ukrainian developer convicted in Switzerland was found to have developed MegaCortex alongside LockerGoga and Nefilim.
MegaCortex uses the open-source Mbed Crypto library and generated AES keys to encrypt files. Its execution architecture separates file discovery from encryption and coordinates parent and child processes through shared memory. An analyzed version normally runs two encryption workers concurrently, with each terminating after processing ten files. Selected system files and directories are excluded to preserve operating-system functionality. The malware decrypts an embedded payload directly into memory and uses DLL injection into newly created legitimate Windows host processes.
Before encryption, MegaCortex attempts to stop and disable hundreds of services and terminate processes associated with endpoint security, backup software, and investigation tools. It delegates many operations to legitimate Windows utilities and uses native file-access APIs. Later versions manually map a Windows system library to bypass user-mode API hooks. After encryption, it deletes volume shadow copies and wipes free disk space to impede restoration and recovery of deleted files.
Version 4, observed in November 2019, separates scanning and encryption into distinct DLLs and changes administrator-account passwords. MegaCortex has also logged users off, preventing them from regaining access with their previous credentials. It leaves ransom demands, and some variants threaten publication of supposedly stolen information; those threats do not establish a built-in data-exfiltration capability. Its encryption payload does not require autonomous lateral movement or automatic-start persistence, relying instead on attacker-controlled deployment within already compromised networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-3396 — Gandcrab, Lockergoga, Megacortex.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The court found the unnamed Ukrainian man to be the lead developer of the LockerGoga, MegaCortex, and Nefilim ransomware families.
Les attaques ont utilisé trois familles de ransomware : LockerGoga, MegaCortex, Nefilim.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Le suspect est présenté comme le principal développeur des rançongiciels Lockergoga, Megacortex et Nefilim; Stadler Rail a été sommée de payer une rançon en bitcoin.
TTPs et IOCs détectés # TTP # T1486 — Data Encrypted for Impact (Impact) T1489 — Service Stop (Impact)
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
81 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family allegedly developed by the convicted individual and used in worldwide corporate extortion attacks.
Ransomware family mentioned only in passing in relation to an unrelated Swiss criminal sentence.
Ransomware allegedly developed by the convicted suspect and identified as one of the ransomware families involved in attacks against organizations including Spie and Altran in January 2019.
Ransomware family that the convicted developer was found to have developed; the article does not specify its technical functionality beyond ransomware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.