MegaCortex Ransomware Revamps for Mass Distribution

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154
A dangerous enterprise-focused ransomware, MegaCortex, has been retooled to become a weapon for wide-scale attacks.

Previously used only in manual, post-network-exploitation, targeted campaigns on carefully selected targets, MegaCortex now has a second variant that adds automation to the kill chain. This gives the malware a path to wider distribution, according to researchers at Accenture’s iDefense division.
The original version of MegaCortex protected its main payload with a custom password supplied by the adversary for each infection.

“The password requirement…prevented the malware from being widely distributed worldwide and required the attackers to install the ransomware mostly through a sequence of manual steps on each targeted network,” explained Leo Fernandes, senior manager of malware analysis and countermeasures at iDefense, in research shared with Threatpost. “The authors of MegaCortex v2 have redesigned the ransomware to self-execute and removed the password requirement for installation; the password is now hard-coded in the binary.”

Other upgrades in version 2.0 include anti-analysis features within the main malware module, and the functionality to stop and kill a wide range of security products and services automatically. This was also previously manually executed as batch script files on each host, Fernandes said.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top