This Ransomware Was Inspired By The Matrix Movie

May 30, 2019

Written by wukovits

There’s a new threat in the world of ransomware to be aware of, known as MegaCortex. Based on its design, it seems clear that the malware’s authors drew inspiration from the movie, ‘The Matrix.’

It first made an appearance near the start of the year but it wasn’t widely employed by hackers, and as such, it was barely a blip on the radar.

That changed on May 1st of this year, according to the UK digital security company Sophos, which detected a massive usage spike.

Since the start of the year, there have been 76 MegaCortex attacks, with 47 of them occurring since the first of May. This may be an indication that the group behind the software is gearing up for a large-scale assault.  So far, corporate networks in France, Italy, the Netherlands, Ireland, Canada, and the United States have been targeted.

Organizations that have fallen victim to MegaCortex report that the attacks come from a compromised domain controller, which the hackers likely seized via stolen credentials.

Andrew Brandt, of Sophos, had this to say about the matter:

“The attacker issues commands via the compromised DC, which the attacker is remotely accessing using the reverse shell.  The DC uses WMI to push the malware – a copy of PsExec renamed rstwg.exe, the main malware executable, and a batch file – to the rest of the computers on the network that it can reach, and then runs the batch file remotely via PsExec.”

It’s a cunning, well-designed piece of software that terminates 44 different processes and 189 different services. It disables 194 other services in a bid to prevent anything from stopping its spread.

To counter this newly emergent threat, Sophos recommends putting any machine on your corporate network that uses RDP behind a VPN and enable two-factor authentication for all admin passwords.

Used with permission from Article Aggregator

Bayou Tech

We provide solutions for your business. Find out how we can help.

Related Articles

New Graphene Technology May Increase Hard Drive Storage

HDDs are old, well understood technology. They haven't changed much in recent years. In fact, increasingly, people are writing them off, preferring SSDs for their greater speed and smaller size, even though HDDs are less expensive. The clever folks at the University...

Some Amazon Device Features May Have Security Risks

Have you heard of Amazon Sidewalk? If not, it's definitely something you should be aware of. Depending on your point of view, the new feature, which was enabled by default on a wide range of Amazon devices by default on June 8 of this year (2021) is either...

Email Unsubscribe Scam Can Easily Fool Any User

Scammers are increasingly relying on a tried and true bit of social engineering to fool unsuspecting users into unwittingly signing up to receive a flood of additional spam email. They accomplish this by blasting out an email asking recipients if they wish to...

Send us a message

Your message was sent.