Facebook Twitter LinkedIn RSS
    Trending
    • NativeTalk, trusted by enterprises for over a decade, launches all-in-one business app for SMEs across Africa
    • How fintechs are turning Dangote’s IPO into customer magnet
    • Fake FRSC SMS scam drains bank accounts across Nigeria
    • Four early warning signals in SME cash flows that legacy models miss
    • NiRA opens nominations for 9th .ng awards, celebrating Nigeria’s digital excellence
    • Nigeria records 78% growth as NIN hits 142million
    • Adeoye Abodunrin to keynote GrowthX by Techeconomy 2026 as tech, finance experts join lineup
    • NigComSat-2A to expand broadband access across Africa
    Facebook Twitter LinkedIn
    ITPulse.com.ngITPulse.com.ng
    • News
    • Interviews
    • Blogs
    • Analysis
    • Opinion
    • Videos
    • Press Releases
    • Pictures
    • Advertise
    ITPulse.com.ngITPulse.com.ng
    Home»News»Sophos alerts businesses on new ransomware called MegaCortex
    News 3 Mins Read

    Sophos alerts businesses on new ransomware called MegaCortex

    mmBy ITPulseMay 8, 2019
    Facebook Twitter WhatsApp Pinterest LinkedIn Reddit Tumblr Email
    John Shier
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SophosLabs has sent an alert of a new Ransomeware called MegaCortex, which it says is threatening businesses.

    Expatiating on the ransomeware, the global leader in endpoint and network security writes:“MegaCortex was a relatively little-seen malware that suddenly spiked in volume on May 1. Sophos has seen MegaCortex detections in the US, Canada, Argentina, Italy, the Netherlands, France, Ireland, Hong Kong, Indonesia, and Australia.

    “The ransomware has manual components similar to Ryuk and BitPaymer, but the adversaries behind MegaCortex use more automated tools to carry out the attack – this is unique.

    “Up until now, Sophos has seen automated attacks, manual attacks and blended attacks, which typically lean more towards using manual hacking techniques to move laterally; with MegaCortex, Sophos is seeing heavier use of automation coupled with the manual component.

    “This new formula is designed to spread the infection to more victims, more quickly.

    As indicated in the SophosLabs Uncut article, MegaCortex Ransomware Wants to be TheOne, there is no explicit value for the ransom demand in the ransom note.

    The attackers invite victims to email them on either of two free mail.com email addresses and send along a file that the ransomware drops on the victim’s hard drive to request decryption “services.” 

    The ransom note also promises the cyber criminals “will include a guarantee that your company will never be inconvenienced by us,” if the victims pay the ransom, and continues, “You will also receive a consultation on how to improve your company’s cyber security.”

    Sophos has also made the following protection recommendation to businesses:

    “It appears that there’s a strong correlation between the presence of MegaCortex, and a pre-existing, ongoing infection on the victims’ networks with both Emotet and Qbot. If IT managers are seeing alerts about Emotet or Qbot infections, those should take a high priority. Both of those bots can be used to distribute other malware, and it’s possible that’s how the MegaCortex infections got their start.

    “Sophos has not seen any indication so far that Remote Desktop Protocol (RDP) has been abused to break into networks, but we know that holes in enterprise firewalls that allow people to connect to RDP remain relatively common. We strongly discourage this practice and suggest that any IT admin who wishes to do this, put the RDP machine behind a VPN

    “As the attack seems to indicate that an administrative password was abused by the criminals, we also recommend the widespread adoption of two-factor authentication wherever possible

    “Keeping regular backups of your most important and current data on an offline storage device is the best way to avoid having to pay a ransom 

    “Use anti-ransomware protection, such as Sophos Intercept X, to block MegaCortex and future ransomware.

    Commenting on the study, Sophos Senior Security Advisor John Shier, said:“We suspect this is your script kiddie/living-off-the-land ‘mega bundle’ and a good example of what we’ve lately been calling cybercriminal pen-testing.

    “The MegaCortex attackers have taken the blended threat approach and turned it up to 11, by increasing the automated component to target more victims. Once they have your admin credentials, there’s no stopping them. Launching the attack from your own domain controller is a great way for the attackers to inherit all the authority they need to impact everything in an organization.

    “Organizations need to pay attention to basic security controls and perform security assessments, before the criminals do, to prevent attackers like these from slipping through”. 

    John Shier
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    mm
    ITPulse
    • Website
    • Facebook
    • Twitter
    • LinkedIn

    ITPulse is a wholly information technology communication (ICT) news website, with a special focus on the African continent. The website provides up-to-date biz-tech news, analysis and comprehensive and thorough insight into the continent's ICT terrain

    Related Posts

    How fintechs are turning Dangote’s IPO into customer magnet

    September 19, 2026

    Fake FRSC SMS scam drains bank accounts across Nigeria

    September 18, 2026

    Nigeria records 78% growth as NIN hits 142million

    September 17, 2026

    Leave A Reply Cancel Reply

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Latest Posts

    NativeTalk, trusted by enterprises for over a decade, launches all-in-one business app for SMEs across Africa

    September 21, 2026

    How fintechs are turning Dangote’s IPO into customer magnet

    September 19, 2026

    Fake FRSC SMS scam drains bank accounts across Nigeria

    September 18, 2026
    About
    About

    Itpulse.com.ng is a wholly information technology communication (ICT) news website, with special focus on the African continent. The website provides up-to-date biz-tech news, analysis and a comprehensive and thorough insight info the continent's ICT terrain.

    Contact us: editorial@itpulse.com.ng

    Facebook Twitter LinkedIn RSS
    Latest Posts

    NativeTalk, trusted by enterprises for over a decade, launches all-in-one business app for SMEs across Africa

    September 21, 2026

    How fintechs are turning Dangote’s IPO into customer magnet

    September 19, 2026

    Fake FRSC SMS scam drains bank accounts across Nigeria

    September 18, 2026
    Popular Posts

    NativeTalk, trusted by enterprises for over a decade, launches all-in-one business app for SMEs across Africa

    September 21, 2026

    PalmPay’s nightGuard reinforces its ‘PalmPay Dey for You’ promise with added night-time protection

    September 15, 2026

    The Nigerian founder building a structured digital marketplace for Africa’s SMEs

    September 11, 2025
    © 2017 - 2026 Itpulse.
    • Terms & Conditions
    • Privacy Policy
    • Advertise
    • Contact Us

    Type above and press Enter to search. Press Esc to cancel.