Midas is a financially motivated ransomware group active since 2021, based on the Thanos ransomware family.
Analyst brief
Midas is a financially motivated crimeware ransomware group that emerged in October 2021, based on the Thanos ransomware family, written in C# and obfuscated with SmartAssembly. The group employs a double extortion strategy featuring its own data leak site, with ThreatLabz reporting a 2022 incident where the ransomware was slowly deployed over a two-month period. Defenders should focus on detecting long-term covert activity, signs of data exfiltration, and initial access techniques preceding ransomware deployment.
midas
crime
This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler). This ransomware features also its own data leak site as part of its double extortion strategy.