Malware

Bitdefender released a free decryptor for the MegaCortex ransomware

Antivirus firm Bitdefender released a decryptor for the MegaCortex ransomware allowing its victims to restore their data for free.

Antivirus firm Bitdefender released a decryptor for the MegaCortex ransomware, which can allow victims of the group to restore their data for free.

The MegaCortex ransomware first appeared on the threat landscape in May 2019 when it was spotted by security experts at Sophos.

The experts noticed that in MegaCortex attacks other malware like Emotet and Qbot (aka Qakbot) were present in the same network.

Since November 2019, MegaCortex operators started adopting double extortion tactics. The group typically asked ransoms between $20,000 to $5.8 million to receive a decryptor.

In December 2019, the FBI issued a warning to the private industry of cyber attacks involving the LockerGoga and MegaCortex Ransomware.

Bitdefender researchers have developed the decryptor with the support of Europol, the Zürich Public Prosecutor’s Office and Cantonal Police, and researchers from the NoMoreRansom Project.

The tool is an executable that can be downloaded from Bitdefender servers.

MegaCortex ransomwareMegaCortex ransomware

The decryptor also supports the “Scan Entire System” mode which allows users to search for all encrypted files.

The user guide released by the security firm strongly recommends users of maintaining the “Backup files” option enabled.

By checking the backup option, users will see both the encrypted and decrypted files. They can
also find a log describing decryption process in %temp%\BitdefenderLog.txt folder.

“In case of encryption with versions 2-4, please make sure the system contains the
ransom note (e.g. “!!READ_ME!!!.TXT”, “!-!README!-!.RTF”, etc). For encryption with
MegaCortex V1 (the encrypted files have the “.aes128ctr” extension appended), please ensure the
ransom note and TSV log file (e.g. “fracxidg.tsv”) created by the ransomware are present on the
system.” reads an important note included in the manual provided with tool.

In September, the Zürich Public Prosecutor’s Office announced it was planning to release a decryptor after the seizure of decryption private keys from a threat actor who was arrested by Swiss authorities and that is facing hacking and money laundering charges.

“This analysis revealed numerous private keys from ransomware attacks. These keys enable damaged companies and institutions to restore data previously encrypted with the “LockerGoga” or “MegaCortex” malware. In cooperation with Europol, the “No More Ransom” project and the company Bitdefender, a tool is provided that supports the victims in decrypting LockerGoga. This is available at www.nomoreransom.org.” reads a press release published by the Zürich Public Prosecutor’s Office. “MegaCortex decryption tool will be released soon. Victims who are affected by attacks with the malicious programs mentioned are urgently requested to file a criminal complaint in their respective home country if they have not already done so.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

US Government officials targeted with texts and AI-generated deepfake voice messages impersonating senior U.S. officials

FBI warns ex-officials are targeted with deepfake texts and AI voice messages impersonating senior U.S.…

8 hours ago

Shields up US retailers. Scattered Spider threat actors can target them

Google warns that the cybercrime group Scattered Spider behind UK retailer attacks is now targeting…

11 hours ago

U.S. CISA adds Google Chromium, DrayTek routers, and SAP NetWeaver flaws to its Known Exploited Vulnerabilities catalog<gwmw style="display:none;"></gwmw>

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium, DrayTek routers, and SAP NetWeaver…

16 hours ago

Pwn2Own Berlin 2025 Day Two: researcher earned 150K hacking VMware ESXi

On day two of Pwn2Own Berlin 2025, participants earned $435,000 for demonstrating zero-day in SharePoint,…

1 day ago

New botnet HTTPBot targets gaming and tech industries with surgical attacks

New botnet HTTPBot is targeting China's gaming, tech, and education sectors, cybersecurity researchers warn. NSFOCUS …

1 day ago

Meta plans to train AI on EU user data from May 27 without consent

Meta plans to train AI on EU user data from May 27 without consent; privacy…

2 days ago