Uptime Hamster: 11d 16h 42mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza midas

midas

2 incidentes 0 paises 1 sectores ransomware RU Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Midas is a Ransomware-as-a-Service (RaaS) operation that first emerged in October 2021, evolving directly from the Haron RaaS and building upon the Thanos ransomware builder. This group's primary motivation is financial gain, achieved through a multi-extortion model that involves encrypting victim data and threatening to publicly leak stolen information if ransoms are not paid. A defining characteristic of Midas is its use of custom C# payloads that incorporate heavy obfuscation and often append the '.axxes' extension to encrypted files. The group maintains its own data leak site for exfiltrated victim data, a key component of its double extortion strategy. While sometimes confused with other variants due to its Thanos builder lineage, Midas has also been associated with the 'Axxes Ransomware Group', suggesting a potential rebranding or close operational tie.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownmidasbkic5eyfox4dhnijkzc7v7e4hpmsb2qgux7diqbpna4up4rtdad.onionmidas
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: midas
Tecnicas MITRE
T1566.001, T1486, T1078.001, T1059.003, T1027
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBangladeshBelgiumBermudaBrazilCanadaSwitzerlandChile

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersReal EstateAccommodationAir TransportationManufacturingConstructionPublic AdministrationOil & GasEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com