midas logo

midas

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Midas is a Ransomware-as-a-Service (RaaS) operation that first emerged in October 2021, evolving directly from the Haron RaaS and building upon the Thanos ransomware builder. This group's primary motivation is financial gain, achieved through a multi-extortion model that involves encrypting victim data and threatening to publicly leak stolen information if ransoms are not paid. A defining characteristic of Midas is its use of custom C# payloads that incorporate heavy obfuscation and often append the '.axxes' extension to encrypted files. The group maintains its own data leak site for exfiltrated victim data, a key component of its double extortion strategy. While sometimes confused with other variants due to its Thanos builder lineage, Midas has also been associated with the 'Axxes Ransomware Group', suggesting a potential rebranding or close operational tie.
Tecnicas MITRE
T1566.001, T1486, T1078.001, T1059.003, T1027

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBangladeshBelgiumBermudaBrazilCanadaSwitzerlandChile

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersReal EstateAccommodationAir TransportationManufacturingConstructionPublic AdministrationOil & GasEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com