DarkHydrus__2019__darkhydruns-group-against-middle-east-en.pdf
ID: dd1f3505-5020-486e-ad41-39fbec22d8f8
STIX ID: report--dd1f3505-5020-486e-ad41-39fbec22d8f8
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-01-17
Last Modified Date: 2019-01-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report describes a 2019 DarkHydrus APT campaign against Middle East targets: Arabic lure Excel documents with embedded macros drop an HTA/PowerShell chain that installs a C# backdoor (OfficeUpdateService.exe). The backdoor implements DNS-tunnel C2 (multiple DNS record types and dedicated name servers), can fall back to Google Drive HTTP uploads, performs VM/sandbox detection, establishes persistence, and supports various commands; the report provides code excerpts, MD5 hashes, domains, a PDB path and mitigation advice (disable Office macros).
