ATT&CKGroupsDarkHydrus

DarkHydrus

G0079

Threat group.View on attack.mitre.org

About this group

DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1059.001
PowerShell

DarkHydrus leveraged PowerShell to download and execute additional scripts for execution.

T1187
Forced Authentication

DarkHydrus used Template Injection to launch an authentication window for users to enter their credentials.

T1204.002
Malicious File

DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded.

T1221
Template Injection

DarkHydrus used an open-source tool, Phishery, to inject malicious remote template URLs into Microsoft Word documents and then sent them to victims to enable Forced Authentication.

T1564.003
Hidden Window

DarkHydrus has used -WindowStyle Hidden to conceal PowerShell windows.

T1566.001
Spearphishing Attachment

DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server.

T1588.002
Tool

DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike.

Software3

Campaigns0

None recorded.

References2

  1. Unit 42 DarkHydrus July 2018 Open source
    Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.
  2. Unit 42 Playbook Dec 2017 Open source
    Unit 42. (2017, December 15). Unit 42 Playbook Viewer. Retrieved December 20, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.