Latest Update27/08/2026

Threats Feed

  1. Public

    RogueRobin DNS Tunneling: A Look at DarkHydrus' Cyber Espionage Tactics

    The RogueRobin malware, developed by the DarkHydrus group, employs DNS tunneling for covert communications in cyberattacks targeting government and educational institutions. The malware appears in two variants: a PowerShell and a .NET executable, both facilitating commands and control operations via encoded DNS queries. This series explores differences in their operation, emphasizing persistence methods and anti-analysis tactics. The technical nuances of RogueRobin, including its innovative DNS record types, highlight its role in sophisticated cyber espionage campaigns.

    read more about RogueRobin DNS Tunneling: A Look at DarkHydrus' Cyber Espionage Tactics
  2. Public

    DarkHydrus Resurfaces with New Trojan Leveraging Google Drive for C2 Activities

    DarkHydrus, an adversary group operating primarily in the Middle East, has resumed activities with new tactics, tools, and procedures (TTPs). Recently analyzed by security researchers, the group has been deploying a new variant of the RogueRobin trojan, which now utilizes Google Drive API for command and control (C2) communications. This shift to using legitimate cloud services for C2 indicates an evolution in their operational tactics. The trojan, delivered through macro-enabled Excel documents, exhibits sophisticated evasion techniques, including environment checks and dynamic DNS to mask its C2 communications. The analysis revealed the use of typosquatting and open-source penetration testing tools, underscoring the group’s persistent and evolving threat landscape.

    read more about DarkHydrus Resurfaces with New Trojan Leveraging Google Drive for C2 Activities
  3. Public

    DarkHydrus Exploits Open-Source Tools in Cyberattacks Against Middle Eastern Governments and Academia

    Palo Alto Unit42 documents DarkHydrus conducting credential harvesting attacks against government entities and educational institutions in the Middle East using the open-source Phishery tool, with the campaign active from at least September 2017 through June 2018. Phishery performs two functions: it injects a remote template URL into Word documents (using the Office attachedTemplate technique) and hosts a C2 server to capture credentials entered into the authentication dialog box that Microsoft Office automatically presents when attempting to load the remote template. DarkHydrus used three malicious Word documents in this campaign. The September 2017 document displayed an employee survey as the decoy, and the November 2017 document displayed what appeared to be an internal password handover form — suggesting the actor may have had prior access to the organization's internal materials. The June 2018 document was empty after credential theft. In all cases, when the user opened the document, Word displayed a dialog asking them to authenticate to connect to a remote resource. DarkHydrus' C2 domain 0utl00k[.]net was engineered to resemble Microsoft Outlook's legitimate "outlook.com" domain. For the June 2018 attack, the specific subdomain used matched the name of the targeted educational institution — making the dialog appear to be an internal login prompt — significantly increasing the likelihood of credential submission. Unit42 confirmed DarkHydrus used Phishery by recreating the tool's output and matching the remote template path exactly, then successfully capturing test credentials via the same C2 flow. The use of an open-source tool is consistent with DarkHydrus's broader pattern of leveraging freely available offensive tools rather than developing custom malware.

    read more about DarkHydrus Exploits Open-Source Tools in Cyberattacks Against Middle Eastern Governments and Academia
  4. Public

    DarkHydrus Targets Middle Eastern Government with RogueRobin Payloads

    Palo Alto Unit42 introduces DarkHydrus — a previously undisclosed threat group — and documents their July 2018 attack on at least one Middle Eastern government agency using a novel delivery mechanism: malicious Excel Web Query (.iqy) files hidden inside password-protected RAR archives sent via spearphishing. The .iqy file (credential.iqy) contains a single URL pointing to micrrosoft[.]net, which Excel natively fetches on open. The retrieved releasenotes.txt file contains an Excel formula that launches a cmd.exe subprocess to run a PowerShell one-liner, downloading and executing winupdate.ps1 — RogueRobin — from the same server. Both consent dialogs (one for remote data, one for command prompt execution) must be accepted by the user, making social engineering the critical success factor. RogueRobin performs five WMI-based sandbox checks (BIOS version for VBOX/bochs/qemu/virtualbox/vm strings, XEN manufacturer, physical memory <2.9GB, CPU cores ≤1) and enumerates processes for Wireshark and Sysinternals before proceeding. If checks pass, it writes OneDrive.ps1 to %APPDATA% and creates a startup folder shortcut (OneDrive.lnk) for persistence. All C2 communication uses a custom DNS tunneling protocol, testing eight DNS record types (A, AAAA, AC, CNAME, MX, TXT, SRV, SOA) on first run and using the first to receive a response for all subsequent communications. Each DNS query encodes a system ID, job ID, data offset, and base64-encoded data chunk in the subdomain. The eight C2 domains all spoof well-known security vendor brands (Cisco AnyConnect, F5 BIG-IP, Fortiweb, Kaspersky, MikroTik, OWA365, Symantec, Windows Defender). Infrastructure pivoting linked these domains through shared name servers (ns102/ns103.kaspersky[.]host) and revealed overlapping infrastructure with a second DarkHydrus credential harvesting campaign (0utl00k[.]net) and possible Copy Kittens connections (cisc0[.]net, per ClearSky reporting — unconfirmed by Unit42). Unit42 assesses DarkHydrus has been active since at least January 2016 and historically relied on open-source tools (Meterpreter, Cobalt Strike, Empire, Veil, Mimikatz) before pivoting to the custom RogueRobin payload in this campaign.

    read more about DarkHydrus Targets Middle Eastern Government with RogueRobin Payloads