DarkHydrus
Named by Palo AltoSuspected state sponsor: Islamic Republic of IranDarkHydrus is an Iranian-linked cyber espionage group active since at least 2016, first named by Palo Alto Networks Unit 42. The group targets government agencies and academic institutions primarily across the Middle East using spear phishing with macro-enabled Office documents — including malicious Excel Web Query (.iqy) files — to deliver its custom RogueRobin trojan. RogueRobin is notable for using DNS tunneling as its primary command and control channel, with an optional fallback to the Google Drive API enabling communications to blend into legitimate cloud service traffic. The group also employs AppLocker bypass techniques via regsvr32.exe, sandbox detection, and debugger checks for anti-analysis. Infrastructure overlaps with OilRig and CopyKittens have been noted by researchers, placing DarkHydrus within the broader Iranian state espionage ecosystem. Public reporting on the group is concentrated between 2016 and early 2020.
Targeted Regions
Middle EastMiddle East
Jan 2017 ~ Jul 2018
Sep 2017 ~ Aug 2018 Jan 2017 ~ Jul 2018
Sep 2017 ~ Aug 2018 Jan 2017 ~ Jul 2018
Sep 2017 ~ Aug 2018 Jan 2017 ~ Jul 2018
Dec 2018 ~ Jan 2019
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.