DarkHydrus
Overview
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.
Naming & attribution
DarkHydrus is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here. Activity attributed since at least 2016.
| Name | First reported by |
|---|---|
| DarkHydrus | Falcone, R., et al |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1187Forced Authentication — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Nomadic Octopus Russia — 4 shared techniques (40% overlap)
- TA459 China — 3 shared techniques (33% overlap)
- Ferocious Kitten Iran — 3 shared techniques (30% overlap)
- Gallmaker — 3 shared techniques (30% overlap)
- Gorgon Group Pakistan — 5 shared techniques (28% overlap)
- IndigoZebra China — 3 shared techniques (27% overlap)
TTPs — 7 techniques across 5 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1059.001PowerShell -
T1204.002Malicious File
Stealth
-
T1221Template Injection -
T1564.003Hidden Window
Credential Access
-
T1187Forced Authentication
Tools & malware (3)
Mimikatz · RogueRobin · Cobalt Strike
Reporting (2)
- New Threat Actor Group DarkHydrus Targets Middle East Government — Falcone, R., et al
- Unit 42 Playbook Viewer — Unit 42