Hydraq

S0203

Malware.View on attack.mitre.org

About this malware

Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more recent campaigns by other Chinese actors, possibly including APT17.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1005
Data from Local System

Hydraq creates a backdoor through which remote attackers can read data from files.

T1007
System Service Discovery

Hydraq creates a backdoor through which remote attackers can monitor services.

T1012
Query Registry

Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys.

T1016
System Network Configuration Discovery

Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.

T1027
Obfuscated Files or Information

Hydraq uses basic obfuscation in the form of spaghetti code.

T1048
Exfiltration Over Alternative Protocol

Hydraq connects to a predefined domain on port 443 to exfil gathered information.

T1057
Process Discovery

Hydraq creates a backdoor through which remote attackers can monitor processes.

T1070.004
File Deletion

Hydraq creates a backdoor through which remote attackers can delete files.

T1082
System Information Discovery

Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed.

T1083
File and Directory Discovery

Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives.

T1105
Ingress Tool Transfer

Hydraq creates a backdoor through which remote attackers can download files and additional malware components.

T1112
Modify Registry

Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys.

T1113
Screen Capture

Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop of an infected host.

T1129
Shared Modules

Hydraq creates a backdoor through which remote attackers can load and call DLL functions.

T1134
Access Token Manipulation

Hydraq creates a backdoor through which remote attackers can adjust token privileges.

View all 19 procedure examples

Groups that use it2

Campaigns0

None recorded.

References8

  1. ASERT Seven Pointed Dagger Aug 2015 Open source
    ASERT. (2015, August). ASERT Threat Intelligence Report – Uncovering the Seven Pointed Dagger. Retrieved March 19, 2018.
  2. FireEye DeputyDog 9002 November 2013 Open source
    Moran, N. et al.. (2013, November 10). Operation Ephemeral Hydra: IE Zero-Day Linked to DeputyDog Uses Diskless Method. Retrieved November 17, 2024.
  3. FireEye Sunshop Campaign May 2013 Open source
    Moran, N. (2013, May 20). Ready for Summer: The Sunshop Campaign. Retrieved November 17, 2024.
  4. MicroFocus 9002 Aug 2016 Open source
    Petrovsky, O. (2016, August 30). “9002 RAT” -- a second building on the left. Retrieved February 20, 2018.
  5. PaloAlto 3102 Sept 2015 Open source
    Falcone, R. & Miller-Osborn, J. (2015, September 23). Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media. Retrieved March 19, 2018.
  6. ProofPoint GoT 9002 Aug 2017 Open source
    Huss, D. & Mesa, M. (2017, August 25). Operation RAT Cook: Chinese APT actors use fake Game of Thrones leaks as lures. Retrieved March 19, 2018.
  7. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  8. Symantec Trojan.Hydraq Jan 2010 Open source
    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.