Description
[MegaCortex](https://attack.mitre.org/software/S0576) is ransomware that first appeared in May 2019. (Citation: IBM MegaCortex) [MegaCortex](https://attack.mitre.org/software/S0576) has mainly targeted industrial organizations. (Citation: FireEye Ransomware Disrupt Industrial Production)(Citation: FireEye Financial Actors Moving into OT)
External References
Techniques Used by This Malware
- T1055.001 — Dynamic-link Library Injection
- T1059.003 — Windows Command Shell
- T1083 — File and Directory Discovery
- T1106 — Native API
- T1112 — Modify Registry
- T1134 — Access Token Manipulation
- T1140 — Deobfuscate/Decode Files or Information
- T1218.011 — Rundll32
- T1486 — Data Encrypted for Impact
- T1489 — Service Stop
- T1490 — Inhibit System Recovery
- T1497.001 — System Checks
- T1531 — Account Access Removal
- T1561.001 — Disk Content Wipe
- T1562.001 — Disable or Modify Tools
- T1588.003 — Code Signing Certificates