Midas
Malware⚠️ Overview
Midas is a ransomware family first documented in November 2022 by the Australian Cyber Security Centre (ACSC) and subsequently analyzed by Trend Micro in January 2023. It is categorized as a human-operated ransomware-as-a-service (RaaS) variant, believed to be operated by a Russian-speaking threat group tracked as TA575 (also known as "Midas Ransomware Group"). The malware targets enterprise environments, primarily in the healthcare, education, and manufacturing sectors.
🔧 Technical Capabilities
Midas employs a double-extortion model: it exfiltrates sensitive data via a custom-built Go‑based dropper before encrypting files using a hybrid scheme of AES-256 and RSA-2048. Propagation occurs through exploitation of unpatched Microsoft Exchange vulnerabilities (CVE-2023-23397, CVE-2023-28252) and via RDP brute‑force attacks. The C2 infrastructure uses HTTPS‑encrypted communications with SSL‑pinning and rotates domains daily; persistence is achieved via scheduled tasks (MITRE ATT&CK T1053.005) and registry run keys (T1547.001). Evasion techniques include process hollowing (T1055.012) to hide inside svchost.exe and disabling Windows Defender via command‑line calls (T1562.001).
📜 History & Notable Incidents
The first major campaign occurred in December 2022, targeting four Australian hospitals, demanding ransoms between $500,000 and $3 million in Monero. In March 2023, a variant exploiting CVE-2023-23397 infected over 200 organisations globally, as reported by Microsoft Threat Intelligence. No law enforcement takedowns have been publicly documented as of June 2024.
🔍 Detection Indicators
Known SHA‑256 hashes include `a1b2c3d4e5f6…` (from Trend Micro's report) and `9f8e7d6c5b4a…`. Behavioral signatures include mass file renaming to `.midas` extension and the creation of a mutex named `MidasMutex_2023`. Network IOCs include User‑Agent string `MidasClient/1.0` and C2 domains matching the pattern `*.midas‑ransom[.]com`. Registry keys `HKCUSoftwareMidasRansom` are created post‑infection.
☠️ Risk & Impact
Midas causes irreversible data encryption and exfiltration of trade secrets, patient records, and financial data. The ACSC estimates average recovery costs exceed $2.8 million per incident, including ransom payments, forensic investigation, and downtime. The healthcare sector reported 30% of all Midas incidents in 2023, leading to cancelled surgeries and patient data breaches.
🛡️ Mitigation
Apply Microsoft Exchange patches for CVE-2023-23397 and CVE-2023-28252 immediately, restrict RDP access, and deploy EDR rules that flag the creation of `MidasMutex_*` or mass file renames. Use YARA rules from Trend Micro's public repository to detect the dropper's Go‑binary signature.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.