Tuesday, March 4, 2025
HomeComputer SecurityNew MegaCortex Ransomware Attack on a Large Number of Enterprise Networks using...

New MegaCortex Ransomware Attack on a Large Number of Enterprise Networks using Red-Team Attack Tools

Published on

SIEM as a Service

Follow Us on Google News

A new ransomware strain MegaCortex leverages both automated and manual components to infect a large number of victims around the world including Italy, the United States, Canada, the Netherlands, Ireland, and France.

Security researchers from Sophos detected a sudden spike in a number of enterprise networks on Wednesday with a new strain of ransomware dubbed MegaCortex.

The ransomware includes both automated and manual components, but it invokes a higher amount of automation to infect a number of victim’s.

According to Sophos, the attackers used “common red-team attack tool script to invoke a meterpreter reverse shell in the victim’s environment and the chain uses PowerShell scripts, batch files to trigger the malware.

The attack starts with a compromised domain controller within the enterprise network, attackers execute a highly obfuscated PowerShell script.

From the compromised domain controller attacker pushes the main malware and the batch file to other machines in the network and execute them remotely via PsExec.The batch files contain a list of commands that kills a number of security software.

The final step of the batch file is to invoke winnit.exe to drop and execute a DLL payload that performs encryption. The encryption payload is digitally-signed by a certificate.

“There have been (so far) 76 confirmed attacks stopped by Intercept X since February, with 47 of those (or about two-thirds of the known incidents) happening in the past 48 hours. Each attack targeted an enterprise network and may have involved hundreds of machines,” reads Sophos report.

After encryption, it adds an eight-random-letter extension to the infected files and drops a plain text file on the root of the victim’s hard drive, which asks victim’s to purchase a software to decrypt the data.

Indicators of Compromise

IP address/domains
Meterpreter’s reverse shell C2 address
89.105.198.28
File hashes
Batch script:
37b4496e650b3994312c838435013560b3ca8571
PE EXE:
478dc5a5f934c62a9246f7d1fc275868f568bc07
Secondary DLL memory injector:
2f40abbb4f78e77745f0e657a19903fc953cc664

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read

Hackers Offered IoT Botnet as Service “TheMoon” : Botnet-as-a-Service

Hackers Exploiting ThinkPHP Vulnerability To Expand Hakai and Yowai Botnets

New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform 

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to...

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass...