Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

New Malware Targeting Windows And Other Operating Systems

New Malware Targeting Windows And Other Operating Systems

Rodney Hall By Rodney Hall Updated Jul 2024 3 min read Share

Researchers on the Global Research and Analysis Team (GReAT) at Kaspersky Lab have recently discovered a new malware strain dubbed PyMICROPSIA, currently being used by a group tracked as AridViper.

AridViper operates primarily in the Middle East, focusing mainly on Palestine, Egypt, and Turkey. Their malware was designed specifically to attack Windows-based machines.

The group hasn't been terribly active, having compromised a relatively modest 3,000 or so machines since they appeared on Kaspersky's radar in 2015. That, however, may be changing.

Recent samples of the code reveal that AridViper is continuing to develop their info-stealing malware. They're arming it with new capabilities and expanding their reach by building in architecture that will allow them to begin attacking machines running both Linux and MacOS.

In terms of new capabilities, AridViper seems to be pulling out all the stops. Not all of these have been activated yet, but hooks are now in the code to build out additional functions.

The Other Functions Include:

  • File uploading
  • Payload download and execution
  • Screen captures
  • File compression for easier exfiltration
  • Collection of process information which would allow killing system processes
  • File deletion
  • Automatic reboot
  • Disabling Outlook processes
  • Creating, deleting, compressing and exfiltrating files and folders
  • Collecting information from USB drives
  • Audio recording
  • And more

All this, in addition to the malware's current info-stealing capabilities, which include the ability to steal credentials from browsers, clearing browser histories, keylogging and the like.

All that to say, if AridViper completes development on all the functionalities listed above and builds out the capability to deploy their malware against Linux and MacOS machines, it will be a dangerous strain indeed.

If you have business dealings in the Middle East, you may have already run afoul of this particular strain. Even if you don't, this is clearly one to watch for as AridViper seems intent on flexing its muscles in the months ahead.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Rodney Hall

About The Author

Rodney Hall · President & COO

Rodney Hall is the President and COO of Securafy, with 2 decades of experience in IT service management and operations.

He writes about the less glamorous but essential side of IT: support systems, documentation, business continuity, recurring issues, downtime, and the processes that keep client environments running well. His perspective comes from years spent improving how service is delivered, how teams respond, and how small problems are prevented from becoming much larger ones.

Outside of work, Rodney enjoys home improvement projects, woodworking, and dirt bike riding. His personal mission mirrors Securafy’s: helping businesses stay secure, compliant, and ready for whatever comes next.

Writes about: Managed IT, IT operations, service delivery, business continuity, downtime prevention, support processes, operational risk

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime