ATT&CKReferencesSymantec Trojan.Hydraq Jan 2010

Symantec Trojan.Hydraq Jan 2010

Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can read data from files.

T1007
System Service Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor services.

T1012
Query Registry
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys.

T1016
System Network Configuration Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.

T1027
Obfuscated Files or Information
MalwareHydraq

Hydraq uses basic obfuscation in the form of spaghetti code.

T1057
Process Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor processes.

T1070.004
File Deletion
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can delete files.

T1083
File and Directory Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives.

T1105
Ingress Tool Transfer
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can download files and additional malware components.

T1112
Modify Registry
MalwareHydraq

Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys.

T1129
Shared Modules
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can load and call DLL functions.

T1543.003
Windows Service
MalwareHydraq

Hydraq creates new services to establish persistence.

T1685.005
Clear Windows Event Logs
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can clear all system event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.