MegaCortex is a ransomware family first discovered in July 2019 by Malwarebytes and later analyzed by Sophos. It is operated by an as‑yet‑unattributed threat actor who manually deploys the ransomware after gaining initial access, typically through compromised RDP or phishing campaigns. Categorized as big‑game‑hunting ransomware, MegaCortex is designed to encrypt enterprise networks and demand high ransoms, often in excess of six figures.
MegaCortex propagates laterally using PsExec and Cobalt Strike beacons, leveraging stolen credentials and existing network shares. The primary attack vector is weak or brute‑forced RDP (Remote Desktop Protocol) credentials, though initial access via phishing emails containing malicious macros has also been observed. The ransomware communicates with a hard‑coded C2 infrastructure via HTTP and HTTPS, often hosted on bulletproof hosting services. Persistence is achieved by installing a service named “MegaCortex” or by modifying Windows services to execute the payload on startup. Evasion techniques include disabling Windows Defender, stopping Volume Shadow Copy Service (VSS) with the command vssadmin delete shadows /all /quiet, and terminating more than 180 services and processes related to backups, databases, and security software. The encryption algorithm uses AES‑256 combined with RSA‑2048, and it appends the extension .m3g0c0rt3x or .vbestcov to encrypted files.
MegaCortex first appeared in July 2019, targeting mid‑to‑large enterprises in North America and Europe. Notable victims include a multinational logistics company and several healthcare organizations, though specific names remain undisclosed in public reports. In 2020, Europol’s Joint Cybercrime Action Taskforce (J‑CAT) led an operation that disrupted infrastructure used by multiple ransomware groups, including some infrastructure shared by MegaCortex operators; however, no direct takedown of the group has occurred. The malware does not have any associated CVEs because it does not exploit a specific software vulnerability — it relies on human‑operated access. MITRE ATT&CK lists it under software ID S0498.
Known file hashes are not broadly published, but behavioral indicators include the creation of the registry key HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMegaCortex and the presence of a ransom note named !-READ-ME-!.txt or !-RECOVER-ME-!.txt. Network IOCs include outbound connections to IP ranges commonly associated with bulletproof hosting (e.g., 45.33.32.0/24, 89.248.165.0/24) and User‑Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 used by Cobalt Strike beacons. The mutex name Globalmega_cort3x has been observed in some samples.
MegaCortex causes data encryption of critical business files, often resulting in prolonged operational downtime. While no public evidence of data exfiltration exists in early variants, later versions incorporate data‑theft capabilities before encryption, increasing the risk of data breaches. The highest impact is seen in the manufacturing, healthcare, and logistics sectors, where ransom demands average between $500,000 and $2 million. Financial losses stem not only from ransom payments but also from incident response, system restoration, and regulatory fines.
Defenders should enforce multi‑factor authentication on RDP, restrict administrative privileges, and implement network segmentation to limit lateral movement. Detection rules should monitor for suspicious PsExec and Cobalt Strike activity using Sysmon or EDR tools, and organizations should maintain offline backups regularly. The MegaCortex detection rule in Sigma (https://github.com/SigmaHQ/sigma) covers process creation events for the ransomware’s execution chain.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.