Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
7
techniques
3
software
9,349
corpus matches
profile
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.
techniques
7 attributed · most-instrumented first
software
3 malware & tools attributed
Mimikatz
S0002
Cobalt Strike
S0154
RogueRobin
S0270
read this carefully
9,349 corpus matches is not attribution
That count is indicators which exhibit techniques DarkHydrus is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
stealth
showing 30 of 9,349