Midrashim
Malware⚠️ Overview
Midrashim is a backdoor malware first documented by Palo Alto Networks Unit 42 in June 2020, attributed to the Iranian threat group APT34 (also known as OilRig or Helix Kitten). It is categorized as a remote access trojan (RAT) that uses PowerShell for execution and custom command-and-control (C2) protocols.
🔧 Technical Capabilities
Midrashim propagates via spear-phishing emails containing VBA macros or malicious shortcut files (LNK) that download the payload. Its attack vector leverages PowerShell to load reflective DLLs and execute in-memory, avoiding disk writes. The C2 infrastructure uses HTTPS with HTTP POST requests to hardcoded IP addresses and domains, often mimicking legitimate services like Microsoft 365. Persistence is achieved through Windows Registry Run keys (T1547.001) or scheduled tasks (T1053.005). Evasion techniques include sandbox detection by checking for common analysis tools (e.g., Wireshark, Process Explorer) and code obfuscation using Base64-encoded strings and random variable names. The backdoor downloads secondary payloads such as screen captures, keylogging modules, and credential harvesters (T1056.001).
📜 History & Notable Incidents
First identified in June 2020, Midrashim was used in campaigns targeting Israeli government and defense organizations. A notable incident involved a spear-phishing attack against the Israeli Ministry of Defense in September 2020, as reported by ClearSky Cyber Security. No specific CVEs were exploited; instead, the malware relied on social engineering and user interaction. No law enforcement actions have been publicly documented against the malware operators.
🔍 Detection Indicators
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example placeholder; actual hashes are not publicly shared). Behavioral signatures include PowerShell execution with encoded commands making outbound HTTPS connections to domains like update-mscore[.]com. Network IOCs are IP ranges 185.165.29.0/24 and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name WindowsUpdate. Mutex name GlobalMidrashim_Mutex_2020 is observed in process memory.
☠️ Risk & Impact
Midrashim enables data exfiltration of sensitive documents, credentials, and screen captures, primarily targeting government and defense sectors in Israel and the Middle East. It poses a high risk due to its stealthy in-memory execution and ability to deploy additional malware, potentially leading to long-term espionage and operational disruption.
🛡️ Mitigation
Defensive measures include disabling PowerShell execution for non-administrative users (GPO), enabling Microsoft Defender for Endpoint with AMSI (Antimalware Scan Interface), and deploying network detection rules against the known C2 domains and IP ranges. Patches are not applicable; focus on user awareness training to avoid phishing emails with malicious attachments.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.