Stakeholders in the security industry have once again joined forces to give ransomware victims a way to mitigate the worst effects of a breach with MegaCortex’s new decryption tool.
A new decryption tool allows victims of the variant to restore their files for free.
It was announced by Bitdefender, but the security vendor acknowledges that the tool was created in collaboration with Europol, the No More Ransom Project, the Zurich Public Prosecutor’s Office, and the Zurich State Police.
Interestingly, the announcement of this antimalware vendor cited October 2021 news. In this news, 12 of him have been arrested in connection with the Dharma, MegaCortex, and LockerGoga ransomware families.
The arrest of what Europol described as a “high-value target” may have ultimately led to the development of the MegaCortex decryption program.
A statement released by the Zurich Public Prosecutor’s Office in September 2022 revealed something similar, with investigators claiming they were able to recover multiple private keys used by the attackers.
“These keys allow victim companies and institutions to recover data previously encrypted by LockerGoga or MegaCortex malware,” it explains.
“We are working with Europol, the No More Ransom Project, and Bitdefender to provide a tool to help victims decrypt LockerGoga. It is available at www.nomoreransom.org. MegaCortex decryption tool. will be released soon.”
LockerGaga decryptor was released last September when it was announced.
Together, the three variants are estimated to have infected 1,800 victims in 71 countries.
MegaCortex was first discovered in May 2019. Victims were shown a ransom note containing various references to the 90s cult film The Matrix. The name of the subspecies reflects the name of the company (MetaCortex) that the movie’s hero, his Neo, works for.
Some victims of the targeted companies were asked to pay millions of dollars in ransoms for decryption keys, and the group stole the data and threatened to leak it. , was also one of the first groups to use the double extortion tactic.