Researchers identified PyMICROPSIA, a Python-based information-stealing Trojan linked to the AridViper threat group and tied to the broader MICROPSIA malware family. The malware targets Windows systems and supports espionage-focused capabilities including browser credential theft, screenshot capture, audio recording, USB data collection, file exfiltration, Outlook data theft, and remote command execution. It communicates with command-and-control infrastructure over HTTP POST requests using multiple URI paths and themed command names, while also downloading additional payloads for keylogging and persistence through a startup shortcut.
The attribution builds on earlier reporting around MICROPSIA and related AridViper activity, including prior campaigns using Delphi-based malware associated with Palestinian targeting themes. Researchers said PyMICROPSIA shares code overlaps, similar C2 path structures, use of RAR archives for exfiltration, themed naming conventions, and Arabic-language comments found in earlier tooling, indicating the group is evolving an established espionage platform rather than introducing an entirely new malware lineage. Active-development indicators, including incomplete or unreachable code branches, suggest the toolset was still being refined as it was deployed.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported a new Python-based information-stealing Trojan named PyMICROPSIA, describing its espionage capabilities, supporting payloads, and ties to the existing MICROPSIA malware family. The researchers attributed the malware to AridViper based on code overlaps, C2 similarities, exfiltration methods, naming conventions, and Arabic-language comments.
Radware published a blog post analyzing MICROPSIA malware, adding public reporting on the malware family later linked to PyMICROPSIA and AridViper.
Cisco Talos published research on a Delphi-based malware campaign associated with targeting Palestine, documenting earlier activity tied to what later reporting connects with the MICROPSIA/AridViper cluster.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
blog.radware.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.