
A new ransomware, called MegaCortex, has been discovered carrying out attacks against entities in the US, Canada, France, the Netherlands, Ireland, and Italy. The ransomware uses both automated and manual means in an attempt to infect as many victims as possible.
According to Sophos researchers who discovered the new MegaCortex campaign, the cybercriminals exploiting these ransomware strains appear to be fans of the movie Matrix, as the ransom note accompanying the attack is “read in the voice and rhythm of the character Morpheus.”
"The malware also uses a large batch file to terminate running programs and stop a large number of services, many of which appear to be security or protection-related," said Sophos researcher Andrew Brandt.
The ransomware first appeared in January 2019, when it was uploaded to VirusTotal. MegaCortex attacks have since escalated.
Since February, 76 confirmed MegaCortex attacks have been detected, with 47 attacks occurring in the past week alone. Each of the attacks targeted a specific entity and may have compromised hundreds of systems.
“While the ransom note does not mention the amount the criminals are demanding, they offer victims a “consultation on how to improve their companies’ security” and “a guarantee that their company will never bother them” – in the future, of course, since they have already been hacked,” Brandt wrote.
Sophos researchers believe the ransomware may have some connections to the Emotet Qbot malware networks, although it is not yet clear whether the malware strains are helping MegaCortex in any way. Both Emotet and Qbot can serve as malware delivery mechanisms. Emotet has been used as such to deliver the Trickbot malware.
Some security experts believe that MegaCortex is delivered via Rietspoof. Sophos researchers believe that attackers operating through MegaCortex may also begin exploiting the Remote Desktop Protocol (RDP) to access and gain control of victims' machines. The researchers urged users to protect RDP machines with a VPN.
“We are still trying to develop a clearer picture of the infection process, but for now it appears that there is a strong correlation between the presence of MegaCortex and a pre-existing, current infection of the victims’ networks with Emotet and Qbot,” Brandt said.
