Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler). This ransomware features also its own data leak site as part of its double extortion strategy. Known victims: 44

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The Midas threat actor is a medium-sophistication criminal group primarily focused on ransomware activities with the goal of achieving financial gain through double extortion tactics. Operating since November 2021, Midas has demonstrated the ability to persist and evolve over time, targeting organizations globally and employing sophisticated techniques such as data exfiltration and encryption. Their use of double extortion strategies, including the creation of a dedicated leak site, underscores their intent to maximize financial gains through both ransom payments and reputational harm.

Goals & Targeting

Midas’ primary objectives are ransomware deployment and financial gain, achieved through double extortion. The group targets organizations without apparent sectoral preference, suggesting a focus on opportunities rather than specific industries. Their choice of victims likely reflects a balance between ease of exploitation and potential for high-value data or assets that would be damaging to disclose publicly.

Enhanced Description

The Midas threat actor is a cybercriminal group specializing in ransomware operations, leveraging a variant of the Thanos ransomware family. This group emerged in late 2021 and has been operational through at least early 2022. Midas employs double extortion tactics, combining ransomware encryption with data theft, to pressure victims into paying ransoms. The ransomware is written in C# and uses SmartAssembly for obfuscation, making it more challenging to analyze and counteract. ThreatLabz reported that Midas was deployed over a two-month period in 2022, indicating a deliberate and measured approach to victimization. The group operates a data leak site as part of its extortion strategy, further intimidating victims by threatening public exposure of stolen information unless demands are met. Midas has targeted at least 44 known victims across various sectors, though specific targeting by industry or region is not fully documented.

Key Capabilities

  • Ransomware deployment
  • Double extortion strategy
  • Data exfiltration
  • Obfuscation techniques with SmartAssembly
  • Spear-phishing capabilities

MITRE ATT&CK Tactics

Credential Access
Data Exfiltration
Defense Evasion

ATT&CK Techniques

T1059.003
T1567
T1486
T1003

Software / Tooling

Midas ransomware variant of Thanos
SmartAssembly obfuscator
Covert communication tools (likely TTP-dependent)

Campaigns & Victims

Midas’ campaign patterns involve a deliberate deployment strategy, with evidence suggesting a two-month operation period in early 2022. The group’s victims include at least 44 entities, though specific details about their targets are limited. Midas has demonstrated the ability to evolve its operations, integrating double extortion tactics as part of its attack vector. Notable for its patient approach and use of a dedicated data leak site, Midas continues to pose a significant threat to organizations lacking robust cybersecurity measures.

IOC Patterns

  • C2 communication patterns associated with Thanos ransomware
  • Obfuscated C# binaries
  • Phishing emails with malicious attachments
  • Presence of encrypted files indicating ransomware activity

Recommended Actions

  • Enhance endpoint detection and response capabilities
  • Implement regular backups with offline storage solutions
  • Monitor for unusual file encryption activities and exfiltration attempts
  • Educate users about phishing and suspicious email patterns
  • Conduct periodic vulnerability assessments to identify potential attack vectors

Suggested Tags

ransomware
double extortion
financial-gain

Confidence Assessment

Confidence in Midas’ threat profile is moderate, as while the group’s operational timeline and basic TTPs are known, specific targeting patterns and precise technical details remain limited. Further intelligence gathering would enhance understanding of their tools, techniques, and victimology.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

4

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
double extortion
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 29, 2021
Last Seen
Apr 14, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.