Midas is a Windows ransomware family that emerged in 2021 and is widely assessed as a Thanos-derived variant built from the leaked Thanos ransomware builder. It is written in C# on the .NET framework and has been observed using SmartAssembly obfuscation. Midas is associated with double-extortion operations in which attackers steal data and threaten public release in addition to encrypting victim systems. It appends an extension based on the targeted organization’s name and typically drops HTA and text ransom notes.
Technically, Midas encrypts files with Salsa20 and protects the symmetric key with RSA public-key encryption. It has been observed terminating processes and services associated with security tools, databases, backup software, and office applications to maximize encryption coverage and reduce interference. It also deletes shadow copies to inhibit recovery and can establish persistence by creating a startup shortcut to reopen the ransom note after reboot.
Intrusions culminating in Midas deployment have relied heavily on hands-on-keyboard tradecraft and legitimate administrative tooling rather than a single distinctive malware delivery chain. Documented attacks involved prolonged dwell time, extensive use of PowerShell, internal RDP, malicious service creation, DLL sideloading through DISM, reflective loading, credential theft with Mimikatz, use of commercial remote access tools, and attempts to disable endpoint protections with Process Hacker before ransomware execution. In at least one investigated case, attackers leveraged administrator-level access to a domain controller, moved laterally across a flat Windows server environment, exfiltrated data, and then deployed ransomware gradually across servers. Midas has been linked to campaigns against enterprise environments, including a technology-sector victim, and operational overlaps have been noted with other Thanos-derived brands such as Haron, Prometheus, and Spook.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Technique ID Technique T1059 Command and Scripting Interpreter
a new, bare-bones ransomware that offloads most of its functionality to a series of PowerShell scripts
For instance, a PowerShell script would execute a Batch file, that in turn would launch a PowerShell script.
They executed commands, launched internal RDP connections, took advantage of already-installed commercial remote access software, exfiltrated data to the cloud, and moved files to and from one of the target’s domain controllers over a two month period.
The earliest indicator of compromise took place on October 13, when logs on one of the compromised domain controllers indicate that a Remote Desktop Protocol (RDP) connection took place between a machine on the internal network of the targeted organization and the domain controller.
late at night of December 7 in the target’s time zone, the attackers began deploying the ransomware binary to machines on the target’s network.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used in a December 2021 intrusion against a technology vendor. The attackers spent weeks moving laterally, using PowerShell, RDP, AnyDesk, TeamViewer, Process Hacker, and backdoored components before deploying Midas binaries across servers.
Ransomware attack leveraging vulnerable remote access services and PowerShell scripts.
A Thanos-derived ransomware variant written in C# that uses double extortion via its own leak site, terminates security/database/backup processes and services, deletes shadow copies, and encrypts files with Salsa20 while protecting keys with RSA.
Ransomware used in a December 2021 attack against a technology vendor. The attackers spent weeks on the network, used PowerShell, RDP, AnyDesk, TeamViewer, Process Hacker, and credential theft before deploying Midas binaries across servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.