Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

5/13/2019
05:25 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

LockerGoga, MegaCortex Ransomware Share Unlikely Traits

New form of ransomware MegaCortex shares commonalities with LockerGoga, enterprise malware recently seen in major cyberattacks.

MegaCortex, a newly discovered form of ransomware that targets global organizations, was found to share similarities with LockerGoga, a known form of malware seen in enterprise attacks.

Sophos researchers published initial findings related to MegaCortex late last week. The active ransomware variant sends victims a note designed to read as if it's from Morpheus, Laurence Fishburne's character in The Matrix. MegaCortex was spotted hitting several enterprise customers across the US, Europe, and Canada, with 47 attack attempts within a 48-hour period.

A few traits of MegaCortex made the campaign stand out. Victims reported the attacks originated from a compromised domain controller, and adversaries used stolen admin credentials to run a PowerShell script using the compromised controller — both traits that make it unique, says Jessica Bair, senior manager of advanced threat solutions at Cisco Systems.

Researchers note this ransomware is mostly seen among businesses with existing Emotet and Qbot infections, both of which can be used as launching points to distribute other malware. Given this, organizations previously exposed to either threat should prioritize remediation.

In the week since its early findings were disclosed, the Sophos team has become aware of more attacks involving MegaCortex and updated their research to reflect additional data on the tools, techniques, and other specifics that were not known at the time of publication.

"Since last week we have learned a lot more of the small details about the behavior and tooling used by MegaCortex," says Chet Wisniewski, Sophos' principal research scientist. "Many of these details are similar or identical to another ransomware named LockerGoga," however, there isn't much code similarity between them. Still, there are a few interesting similarities:

Links to LockerGoga
LockerGoga is a form of ransomware recently used in a major cyberattack against Norwegian aluminum firm Norsk Hydro, where it disrupted critical operations across North America and Europe. The incident forced Norsk Hydro to transition to manual operations at multiple plants; so far, it has cost the manufacturer $40 million. Once on a system, LockerGoga, which appears to be designed for targeted campaigns, changes passwords and forcibly logs victims out of systems.

The two forms of ransomware appear to behave the same way, Wisniewski explains. In both, operators leverage a compromised domain controller to push malware out to machines on a target network. From there, they open a reverse shell from the internal network to one of their command-and-control (C2) servers to execute the attacks. At least one of the C2 addresses that MegaCortex contacts has also been used by LockerGoga, researchers explain in a blog post.

MegaCortex also renames the files it plans to encrypt before encrypting them, which is unusual for ransomware — except LockerGoga, which does the same. "We suspect this may be used to prevent the malware from unintentionally encrypting files twice on an infected machine," says Wisniewski. The tactic has another effect: it makes those renamed files "un-double-clickable" as it removes the file type association of the document with its parent application.

One of the most obvious similarities is the batch file used in the attack, Wisniewski continues. Many researchers think it's "virtually identical" to batch files used to kill processes during LockerGoga attacks. Still, he says, none of the individual similarities are enough to make any attribution to MegaCortex's origin. At this time, they remain a "large number of interesting coincidences."

Contemplating Cryptographic Certificates
MegaCortex uses signed binaries with the common name (CN) mimicking the same CN used in the signed binaries of completely unrelated malware families. For example, researchers queried a CN on the cryptographic certificate used to sign one of the MegaCortex malware executables. They found malware from Rietspoof, a financial-services credential stealer with no code similarity or link to MegaCortex.

"We're not sure why they would do this," says Wisniewski. "Often things are thrown in to confuse those investigating the attacks, a sort of 'false flag operation.'" The certificates for MegaCortex were issued by different authorities from the certificates they were mimicking; for example, that of Rietspoof. Some certificate authorities are now revoking the certificates used in MegaCortex attacks, Wisniewski says.

Investigation into certificates yielded another interesting finding: researchers noticed the address used by the certificate — a street address located in London suburb Romford — is connected to more than 74,000 registered UK businesses. There is also evidence the same address has been used in signing certificates that were then used to sign unrelated malware binaries. They're still looking into this.

"We do not really understand how an apparent residential address ended up being used as a business address for some 74,000+ companies currently or formerly registered in the UK," says Wisniewski, who adds that site for The Companies House — the United Kingdom's registrar for companies — permits visitors to access only the first 1,000 records of this search.

Related Content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
97% of Americans Can't Ace a Basic Security Test
Steve Zurier, Contributing Writer,  5/20/2019
TeamViewer Admits Breach from 2016
Dark Reading Staff 5/20/2019
How a Manufacturing Firm Recovered from a Devastating Ransomware Attack
Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-7201
PUBLISHED: 2019-05-22
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
CVE-2018-7803
PUBLISHED: 2019-05-22
A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TriStation Emulator V1.2.0, which could cause the emulator to crash when sending a specially crafted packet. The emulator is used infrequently for application logic testing. It is susceptible to an attack...
CVE-2018-7844
PUBLISHED: 2019-05-22
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.
CVE-2018-7853
PUBLISHED: 2019-05-22
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading invalid physical memory blocks in the controller over Modbus
CVE-2018-7854
PUBLISHED: 2019-05-22
A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a denial of Service when sending invalid debug parameters to the controller over Modbus.