logo

DarkHydrus__2019__New_Threat_Actor_Group_DarkHydrus_Targets_Middle_East_Government.pdf

ID: 4c34d3e0-d5e9-469c-b03a-5d494d1f13df

STIX ID: report--4c34d3e0-d5e9-469c-b03a-5d494d1f13df

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2019-02-12

Last Modified Date: 2019-02-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzed a targeted DarkHydrus campaign (July 2018) that delivered password-protected RAR attachments containing malicious .iqy Excel Web Query files which cause Excel to fetch and execute a PowerShell backdoor (RogueRobin). The backdoor performs sandbox detection, installs persistence via %APPDATA%\OneDrive.ps1/OneDrive.lnk, and communicates with C2 servers using a custom DNS-tunneling protocol across multiple vendor‑spoofing domains; the report provides extensive IOCs (domains and SHA256 hashes), technical TTPs, and mitigation notes.