Micropsia is a Delphi-based remote access trojan and information-stealing malware family associated with Arid Viper, also known as APT-C-23, Desert Falcon, and Mantis. Publicly identified in 2017, it is used in cyberespionage operations, particularly against Palestinian individuals, activists, and organizations. Its principal implementations target Windows; Python-based and Android variants have also been reported. Delivery campaigns have used spearphishing links, fake news sites, compressed archives, and politically themed decoy documents to entice victims into executing malware.
Micropsia supports remote shell-command execution, file downloading, secondary-payload execution, keylogging, screenshot capture, and data exfiltration. It collects host information, including computer names, usernames, operating-system details, and installed antivirus products, and uses WMI to discover antivirus and firewall software. Some implementations capture screenshots every 90 seconds through the Windows BitBlt API. It searches for Office documents and uses WinRAR to archive and encrypt collected files before exfiltration, storing component outputs in hidden directories. Windows persistence is established through a shortcut in the user's Startup folder. Command-and-control communications use HTTP POST requests, with some variants separating screenshot uploads from other command traffic. In later intrusions, Micropsia has also served as a launcher for additional tools and the Arid Gopher backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
From these programs, we're told, it became clear the team were looking at a variant of Micropsia. This malware was identified in 2017 and is used exclusively by Arid Viper.
We also observed consistent targeting of Palestinian entities in this time period using the group’s staple Micropsia family malware and Pierogi++.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
274 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor used by Mantis that can take screenshots, keylog, and archive files for exfiltration, while also serving to run secondary payloads.
Listed as a tool used by the ALUMINUM SARATOGA threat profile; also listed under ALUMINUM SHADYSIDE tools.
A staple Gaza Cybergang malware family observed in Delphi and Python-based variants. It is used in espionage-oriented campaigns, often deploying Arabic decoy documents focused on Palestinian matters, and has evolved across multiple implementations and naming conventions.
Micropsia is a recurring malware family associated with Arid Viper/APT-C-23 campaigns targeting Palestinian and Israeli victims through phishing and espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.