Ransomware Group intelligence
Midas
InactiveTrack Midas with 44 published victims and 1 known leak locations in a single intelligence view.
Overview
Midas is tracked by Breach House as a ransomware group with 44 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 25m ago | midasbkic5eyfox4dhnijkzc7v7e4hpmsb2qgux7diqbpna4up4rtdad.onion |
Top Activity Sectors (8)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Midas, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: midas executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: midas adds malicious registry run keys to ensure persistence across reboots on compromised systems.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: midas disables antivirus tools and modifies Windows Defender settings to evade detection and persistence.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: midas inserts junk code into legitimate binaries to evade static analysis and behavioral detection tools.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: midas deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: midas discovers remote hosts using nmap scans to map the internal network before spreading ransomware.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: midas scans network shares using net use commands to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: midas exfiltrates stolen data using Python scripts over encrypted C2 channels before deploying encryption.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: midas encrypts victim files using custom ransomware binaries targeting documents and backups across the network.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: midas runs system recovery commands to halt backup restoration processes and lock victim infrastructure.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (44)
Search, filter and paginate the victim timeline for Midas. Showing 1–44 of 44.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Basra Multipurposr Terminal id3179 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SUPREME SERVICES id3111 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Jiangsu Kaili Carpet Co., Ltd. id3110 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New Company 04.2022 id3067 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NetCompany id2946 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bigmtransport id2911 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 1 id2883 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grcouceiro id2837 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | S id2681 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SOUTHWARK METAL MANUFACTURING id2678 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New3 id2621 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New-New2 id2613 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | J id2612 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Keuerleber id2534 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CIG de la Grande Couronne id2529 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | crossroadshealth lake id2457 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New Corp id2299 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MAX International Converters id2283 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NewWave Technologies Inc id2112 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CurIT id2036 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Westrup Company id2035 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GROUP OF COMPANY id2034 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ChaddadGroup id2033 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CRM GROUP id2032 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bouquet Mulligan DeMaio id2031 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | IDSFULFILLMENT id2030 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | RWL GmbH id2029 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EISENBERG HEFLER & LEVY LLP id2028 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | HAMTACO id2027 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CABINET CAZANAVE id2026 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Raisetech id2025 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EPOWER INTERNATIONAL ( SHANGHAl )CO.,LTD. id2024 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dongguan IMR Technology Co., Ltd id2023 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Capital Distributors (S) Pte Ltd id2022 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KPS GROUP id2021 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Shanghai Cyeco Environmental Technology Co., Ltd. id2020 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Xiamen Naier Electronics Co., Ltd. id2019 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Haiti Meat Processing SA id2018 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Consult Three Architects id2017 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Trendico GmbH id2016 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pellisard id2015 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | G.E.W. CORPORATION LIMITED id2014 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Texas Enterprises, Inc (TEI) id2013 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Calibrus id2012 View details | Other | — | ||
|
No additional victim description available. |
|||||