Skip to content

Malware

Midas

This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly.

Midas is a Windows malware family.

Background

Written in C# and protected with SmartAssembly obfuscation, this family surfaced in October 2021 as an offshoot of the Thanos ransomware lineage. ThreatLabz at ZScaler documented a 2022 incident in which the operators rolled Midas out gradually across a victim's environment over roughly two months. In keeping with double-extortion tactics, the group also runs a dedicated data leak site.


Source: Malpedia (Fraunhofer FKIE).