DarkHydrus__2019__DarkHydrus_delivers_new_Trojan_that_can_use_Google_Drive_for_C2_communications.pdf
ID: cda9bcc3-f712-4436-b82a-470031d43d47
STIX ID: report--cda9bcc3-f712-4436-b82a-470031d43d47
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2019-02-12
Last Modified Date: 2019-02-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Palo Alto Unit 42 details DarkHydrus activity delivering a new RogueRobin.NET trojan via macro-enabled Excel documents that drop a C# payload and persist via a startup LNK; the malware uses DNS tunneling (various query types), sandbox and debugger checks, and optionally an alternate Google Drive-based C2 (obtaining OAuth tokens, uploading/downloading files) while leveraging an AppLocker bypass (regsvr32/.sct). The report includes sample hashes, C2 domains, nameservers, mapping of clustered infrastructure, and defensive guidance (WildFire/verdicts, domain classification, AutoFocus tags).
