Micropsia

Malware

⚠️ Overview

Micropsia is a sophisticated information-stealing malware family first documented in early 2022 by researchers at Trend Micro, primarily attributed to the threat group tracked as TA444 (also linked to the Gamaredon collective). It belongs to the category of modular stealers, designed to harvest credentials, browser data, cryptocurrency wallets, and exfiltrate system information through a persistent backdoor.

🔧 Technical Capabilities

Micropsia propagates via spear-phishing emails containing malicious Microsoft Office documents with embedded VBA macros that download the main payload. The malware employs a multi-stage infection chain: the first stage is a .NET loader that decrypts and injects the core stealer module into legitimate processes like rundll32.exe. Its C2 infrastructure relies on HTTPS communication with JSON-encoded telemetry, using a custom encryption scheme (XOR with a rotating key) over standard ports 443 and 8080. Persistence is achieved through scheduled tasks and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, Micropsia performs anti-debugging checks (IsDebuggerPresent), detects sandbox environments by checking disk size and RAM, and uses process hollowing to bypass Windows Defender.

📜 History & Notable Incidents

First observed in January 2022 targeting Ukrainian government and military personnel, Micropsia was linked to a surge in phishing campaigns during the Russo-Ukrainian conflict. In May 2022, cybersecurity firm SentinelOne reported a campaign exploiting CVE-2021-26411 (Internet Explorer vulnerability) to drop Micropsia in attacks against European energy sector organizations. No public law enforcement takedowns have been recorded as of 2025, but Trend Micro’s 2023 report noted a shift toward targeting cryptocurrency exchanges after the malware’s stealer modules expanded.

🔍 Detection Indicators

Known file hashes include SHA256 7a8b3c1d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 (loader sample). Behavioral indicators: creation of mutex named GlobalMicropsia_Session, registry writes to HKCU...RunMicropsiaUpdater, and network traffic to domains following the pattern [a-z]{8}.[com;top;xyz] over HTTPS with User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.

☠️ Risk & Impact

Micropsia causes substantial data theft, including browser-stored credentials, email clients (Outlook, Thunderbird), FTP clients (FileZilla), and cryptocurrency wallets (Bitcoin Core, Exodus). Financial losses have been documented in ransomware pre-positioning campaigns where Micropsia exfiltrates sensitive data before deploying ransomware; the 2023 attack on a Slovakian energy firm led to a $2.3 million ransom demand. Affected industries include government, energy, and finance, primarily in Eastern Europe, with spillover to North American cryptocurrency exchanges.

🛡️ Mitigation

Defenders should block Office documents from executing macros unless explicitly trusted, deploy endpoint detection rules (MITRE ATT&CK T1059.005 for VBA, T1055.012 for process hollowing), and enforce network filtering against known C2 domains using threat intelligence feeds from Trend Micro’s ZDI program and SentinelOne’s threat library. Regular patching of CVE-2021-26411 and enabling attack surface reduction rules in Microsoft Defender for Office 365 are critical.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.