This decryptor was built in cooperation with Europol, the NoMoreRansom Project, the Zürich Public Prosecutor’s Office and the Zürich Cantonal Police.
In October 2021, 12 people ended up busted in an international law enforcement operation against Dharma, MegaCortex and LockerGoga ransomware.
This group was responsible for an estimated 1,800 infections across 71 countries, mostly targeting companies. Following the release of the LockerGoga decryptor, Bitdefender released a universal tool for MegaCortex infections.
Once on the network, some of these cyber actors would focus on moving laterally, deploying malware such as Trickbot, or post-exploitation frameworks such as Cobalt Strike or PowerShell Empire, to stay undetected and gain further access.
The criminals would then lay undetected in the compromised systems, sometimes for months, probing for more weaknesses in the IT networks before moving on to monetizing the infection by deploying a ransomware.
The effects of the ransomware attacks were devastating as the criminals had the time to explore the IT networks undetected. A ransom note was then presented to the victim, which demanded the victim pay the attackers in Bitcoin in exchange for decryption keys.
Victims with data encrypted by versions 2 through 4 need the ransom note (e.g. “!!READ_ME!!!.TXT”, “!-!README!-!.RTF”, etc) present. MegaCortex V1 decryption (the encrypted files have the “.aes128ctr” extension appended) requires the presence of the ransom note and TSV log file (e.g. “fracxidg.tsv”) created by the ransomware.
If a company ended up attacked and affected by MegaCortex, it can now use the tool to recover files. There is a step-by-step tutorial on how to operate the decryptor in both single-computer and network modes.
Click here to download the decryptor from Bitdefender.
.

