DarkHydrus__2019__New_Threat_Actor_Group_DarkHydrus_Targets_Middle_East_Government.pdf
ID: 4c34d3e0-d5e9-469c-b03a-5d494d1f13df
STIX ID: report--4c34d3e0-d5e9-469c-b03a-5d494d1f13df
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2019-02-12
Last Modified Date: 2019-02-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzed a targeted DarkHydrus campaign (July 2018) that delivered password-protected RAR attachments containing malicious .iqy Excel Web Query files which cause Excel to fetch and execute a PowerShell backdoor (RogueRobin). The backdoor performs sandbox detection, installs persistence via %APPDATA%\OneDrive.ps1/OneDrive.lnk, and communicates with C2 servers using a custom DNS-tunneling protocol across multiple vendor‑spoofing domains; the report provides extensive IOCs (domains and SHA256 hashes), technical TTPs, and mitigation notes.
