Micropsia is a Windows-focused information-stealing remote access malware family associated closely with the Arid Viper threat actor, also tracked as APT-C-23, Desert Falcon, and related aliases. First identified in 2017 and commonly described as written in Delphi, the family has been used in espionage operations targeting Palestinian individuals, activists, organizations, and other victims in the Middle East, with broader targeting also reported in Israel, Egypt, the United States, and media-related entities. Variants and closely related evolutions have also appeared in Python and Go-based tooling linked to the same actor ecosystem.
Micropsia is typically delivered through socially engineered lures using politically themed decoy documents and archive-based packaging. Reported delivery methods include spearphishing and malicious archives that unpack the implant while displaying a decoy document to the victim. In some campaigns, operators used fake news themes, shortened links, and credential-harvesting pages alongside malware delivery.
Functionally, Micropsia combines surveillance, host profiling, and theft capabilities. Reported behaviors include keylogging, periodic screenshot capture, collection of the current username and other host identifiers, discovery of installed antivirus and firewall products via WMI, command execution, file collection, and exfiltration of stolen data. Some variants search for documents of interest, especially Microsoft Office files, then invoke archiving utilities to recursively package and encrypt collected material before exfiltration. The malware has also been observed storing component output in hidden directories to reduce user visibility.
For persistence, Micropsia has been observed creating a shortcut in the Windows Startup folder so the implant launches at user logon. In later intrusions, it also served as a launcher or orchestrator for secondary payloads used by Arid Viper, including additional backdoors, tunneling components, and exfiltration utilities. Communications with command-and-control infrastructure have been reported over HTTP POST, with separate tasking and screenshot workflows in some variants.
Micropsia is best understood as a long-running espionage malware family within Arid Viper’s toolkit, emphasizing credential and information theft, victim monitoring, and staged exfiltration from compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
From these programs, we're told, it became clear the team were looking at a variant of Micropsia. This malware was identified in 2017 and is used exclusively by Arid Viper.
We also observed consistent targeting of Palestinian entities in this time period using the group’s staple Micropsia family malware and Pierogi++.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
another method favored by the attackers was the setting up of fake news sites.
Interestingly in some cases the attackers combined an attempt to infect targeted users with malware, with an attempt to steal their credentials via traditional phishing techniques.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The C2 server string in the binary is "obfuscated" in the most basic of senses, with the author adding '@' characters between letters
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The malware communicates with the C2 server via HTTP requests
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
274 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor used by Mantis that can take screenshots, keylog, and archive files for exfiltration, while also serving to run secondary payloads.
Listed as a tool used by the ALUMINUM SARATOGA threat profile; also listed under ALUMINUM SHADYSIDE tools.
A staple Gaza Cybergang malware family observed in Delphi and Python-based variants. It is used in espionage-oriented campaigns, often deploying Arabic decoy documents focused on Palestinian matters, and has evolved across multiple implementations and naming conventions.
Micropsia is a recurring malware family associated with Arid Viper/APT-C-23 campaigns targeting Palestinian and Israeli victims through phishing and espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.