This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler). This ransomware features also its own data leak site as part of its double extortion strategy. Known victims: 44
Objectives
Executive Summary
The Midas threat actor is a medium-sophistication criminal group primarily focused on ransomware activities with the goal of achieving financial gain through double extortion tactics. Operating since November 2021, Midas has demonstrated the ability to persist and evolve over time, targeting organizations globally and employing sophisticated techniques such as data exfiltration and encryption. Their use of double extortion strategies, including the creation of a dedicated leak site, underscores their intent to maximize financial gains through both ransom payments and reputational harm.
Goals & Targeting
Midas’ primary objectives are ransomware deployment and financial gain, achieved through double extortion. The group targets organizations without apparent sectoral preference, suggesting a focus on opportunities rather than specific industries. Their choice of victims likely reflects a balance between ease of exploitation and potential for high-value data or assets that would be damaging to disclose publicly.
Enhanced Description
The Midas threat actor is a cybercriminal group specializing in ransomware operations, leveraging a variant of the Thanos ransomware family. This group emerged in late 2021 and has been operational through at least early 2022. Midas employs double extortion tactics, combining ransomware encryption with data theft, to pressure victims into paying ransoms. The ransomware is written in C# and uses SmartAssembly for obfuscation, making it more challenging to analyze and counteract. ThreatLabz reported that Midas was deployed over a two-month period in 2022, indicating a deliberate and measured approach to victimization. The group operates a data leak site as part of its extortion strategy, further intimidating victims by threatening public exposure of stolen information unless demands are met. Midas has targeted at least 44 known victims across various sectors, though specific targeting by industry or region is not fully documented.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Midas’ campaign patterns involve a deliberate deployment strategy, with evidence suggesting a two-month operation period in early 2022. The group’s victims include at least 44 entities, though specific details about their targets are limited. Midas has demonstrated the ability to evolve its operations, integrating double extortion tactics as part of its attack vector. Notable for its patient approach and use of a dedicated data leak site, Midas continues to pose a significant threat to organizations lacking robust cybersecurity measures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Midas’ threat profile is moderate, as while the group’s operational timeline and basic TTPs are known, specific targeting patterns and precise technical details remain limited. Further intelligence gathering would enhance understanding of their tools, techniques, and victimology.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
4
IOCs
0
Observed Data
0
Tactics