Introduction
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks. Unit 42 DarkHydrus July 2018 Unit 42 Playbook Dec 2017
Activities and Tactics
Country of Origin: 🇮🇷 Iran
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1204.002 Malicious File
- T1187 Forced Authentication
- T1564.003 Hidden Window
- T1059.001 PowerShell
- T1566.001 Spearphishing Attachment
- T1221 Template Injection
- T1588.002 Tool
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- RogueRobin:
MITRE ATT&CK Software
Attribution and Evidence
Country of Origin: Iran Additional attribution information pending cataloguing.
References
[1] mitre-attack [3] Unit 42 DarkHydrus July 2018 Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018. [4] Unit 42 Playbook Dec 2017 Unit 42. (2017, December 15). Unit 42 Playbook Viewer. Retrieved December 20, 2017.