Micropsia is a Delphi-based remote access trojan/backdoor malware family associated with Arid Viper, also known as Desert Falcon, APT-C-23, Mantis, and as part of broader Gaza Cybergang activity. Public reporting places its use since at least 2017 in campaigns primarily targeting Palestinian individuals, activists, law enforcement, government and other Palestinian entities, with some reporting also linking the actor to targeting in Israel and other Middle Eastern sectors. Delivery has been observed via spear-phishing and politically themed Arabic-language lures, including RAR archives containing executables disguised as PDF or document files; related drive-by delivery activity has also been reported.
Observed Micropsia capabilities include remote control of infected Windows systems, downloading and executing additional payloads, acting as a launcher for secondary tools, persistence via a shortcut placed in the user Startup folder, and command-and-control over HTTP POST. It profiles victims by collecting the username, computer name, OS information, and installed security products, including antivirus, antispyware, and firewall products, using WMI queries such as SecurityCenter2/AntiVirusProduct and related classes. Reported collection functions include screenshot capture every 90 seconds via Gdi32.BitBlt, keylogging, microphone recording, and creation of hidden directories to store component output. It can recursively collect files matching predefined extensions and archive them using RAR/WinRAR for exfiltration.
In later Arid Viper operations observed in 2022-2023, updated Micropsia variants were used alongside the Arid Gopher backdoor during intrusions against Palestinian organizations. In that reporting, Micropsia was executed via WMI, used to run secondary payloads, supported screenshot capture, keylogging, and WinRAR-based collection, and was involved in credential theft and exfiltration workflows. Additional reporting also notes ongoing evolution of the family, including Delphi-based and Python-based variants, and Facebook listed related Arid Viper Windows malware variants including Primewire, Fgref, Sears, Rahman, Pierogi, PyMicropsia, and Glasswire. Reported infrastructure associated with Micropsia campaigns includes camilleoconnell[.]website, deangelomcnay[.]news, juliansturgill[.]info, earlahenry[.]com, nicholasuhl[.]website, cooperron[.]me, dorothymambrose[.]live, ruthgreenrtg[.]live, bruce-ess[.]com, and wayne-lashley[.]com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In its most recent attacks, the group used updated versions of its custom Micropsia and Arid Gopher backdoors to compromise targets before engaging in extensive credential theft and exfiltration of stolen data.
We also observed consistent targeting of Palestinian entities in this time period using the group’s staple Micropsia family malware and Pierogi++.
Tools… “NimbleMamba, BrittleBush, LastConn, Micropsia”
35 distinct techniques documented for this family, organized by ATT&CK tactic.
We have also identified drive-by download campaigns which are distributing variants of the same malware, but with different decoy documents.
The group is known for employing spear-phishing emails and fake social media profiles to lure targets into installing malware on their devices.
We identified one specific spear phishing campaign launched against targets within Palestine... using a spear phishing campaign to deliver the MICROPSIA payload... Attached to the email is a .r10 file... The RAR archive contains a single executable file named: InternetPolicy_..._pdf.exe
Micropsia is executed using WMI and its main purpose appears to be running secondary payloads for the attackers.
Three distinct sets of obfuscated PowerShell commands were executed to load a Base64-encoded string, which started embedded shellcode.
Three distinct sets of obfuscated PowerShell commands were executed to load a Base64-encoded string, which started embedded shellcode.
The commands follow the format: ;<cmd_code>;<base64_encoded_supporting_data>; ... The above example would run the ipconfig command on the endpoint... 'cmd' Execute the command specified and send output to C2.
The attackers returned on December 19 to dump credentials before downloading the Micropsia backdoor and Putty... using Certutil and BITSAdmin
The attackers returned on December 19 to dump credentials before downloading the Micropsia backdoor and Putty... using Certutil and BITSAdmin
Three distinct sets of obfuscated PowerShell commands were executed to load a Base64-encoded string, which started embedded shellcode.
When the executable is launched it extracts the decoy document embedded as the PE resource named Resource_1 and opens it.
The .r10 file extension may have been chosen in order to confuse automated file parsing systems... the long name of the file within the archive, along with the ending '_pdf.exe' may have been used to convince victims into thinking that the file is a real PDF file. The icon of executable file itself is that commonly used for PDF files
The attackers returned on December 19 to dump credentials before downloading the Micropsia backdoor and Putty... using Certutil and BITSAdmin
The attackers returned on December 19 to dump credentials before downloading the Micropsia backdoor and Putty... using Certutil and BITSAdmin
Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Confucius has used a file stealer to steal documents and images... Patchwork developed a file stealer to search C:\ and collect files with certain extensions... Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.
In addition to this, Micropsia has its own functionality, such as taking screenshots, keylogging...
In addition to this, Micropsia has its own functionality, such as taking screenshots...
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
On one computer, Micropsia was used to set up a reverse socks tunnel to an external IP address
86 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor used by Mantis that can take screenshots, keylog, and archive files for exfiltration, while also serving to run secondary payloads.
A staple Gaza Cybergang malware family observed in Delphi and Python-based variants. It is used in espionage-oriented campaigns, often deploying Arabic decoy documents focused on Palestinian matters, and has evolved across multiple implementations and naming conventions.
Micropsia is a recurring malware family associated with Arid Viper/APT-C-23 campaigns targeting Palestinian and Israeli victims through phishing and espionage operations.
A custom backdoor used by Mantis/Arid Viper as a primary foothold and payload launcher. It is executed via WMI and is mainly used to run secondary payloads, including Arid Gopher, a reverse SOCKS tunneler, and a data exfiltration tool. It also has native capabilities including screenshot capture, keylogging, and archiving files with WinRAR for exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.