Actors Insights|Latest update24/07/2026

DarkHydrus

Named by Palo AltoSuspected state sponsor: Islamic Republic of Iran

DarkHydrus is an Iranian-linked cyber espionage group active since at least 2016, first named by Palo Alto Networks Unit 42. The group targets government agencies and academic institutions primarily across the Middle East using spear phishing with macro-enabled Office documents — including malicious Excel Web Query (.iqy) files — to deliver its custom RogueRobin trojan. RogueRobin is notable for using DNS tunneling as its primary command and control channel, with an optional fallback to the Google Drive API enabling communications to blend into legitimate cloud service traffic. The group also employs AppLocker bypass techniques via regsvr32.exe, sandbox detection, and debugger checks for anti-analysis. Infrastructure overlaps with OilRig and CopyKittens have been noted by researchers, placing DarkHydrus within the broader Iranian state espionage ecosystem. Public reporting on the group is concentrated between 2016 and early 2020.

First Seen:Jan 2017
Last Seen:Feb 2020
Indexed Reports:4
Public IOCs:94
Cluster: UnclassifiedMitre: DarkHydrusMisp: DarkHydrus
also known as:
LazyMeerkat (Kaspersky)G0079 (Mitre)Obscure SerpensDarkHydrus (Palo Alto)

Targeted Regions

Middle East
ME
Middle East
Middle East
Jan 2017 ~ Jul 2018
Sep 2017 ~ Aug 2018
Jan 2017 ~ Jul 2018
Sep 2017 ~ Aug 2018
Jan 2017 ~ Jul 2018
Sep 2017 ~ Aug 2018
Jan 2017 ~ Jul 2018
Dec 2018 ~ Jan 2019
Jan 2017Aug 2026

Targeted Sectors

Government Agencies and ServicesEducation

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.