Threats Feed|DarkHydrus|Last Updated 29/04/2026|AuthorCertfa Radar|Publish Date07/08/2018

DarkHydrus Exploits Open-Source Tools in Cyberattacks Against Middle Eastern Governments and Academia

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Credential stuffing,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Palo Alto Unit42 documents DarkHydrus conducting credential harvesting attacks against government entities and educational institutions in the Middle East using the open-source Phishery tool, with the campaign active from at least September 2017 through June 2018. Phishery performs two functions: it injects a remote template URL into Word documents (using the Office attachedTemplate technique) and hosts a C2 server to capture credentials entered into the authentication dialog box that Microsoft Office automatically presents when attempting to load the remote template. DarkHydrus used three malicious Word documents in this campaign. The September 2017 document displayed an employee survey as the decoy, and the November 2017 document displayed what appeared to be an internal password handover form — suggesting the actor may have had prior access to the organization's internal materials. The June 2018 document was empty after credential theft. In all cases, when the user opened the document, Word displayed a dialog asking them to authenticate to connect to a remote resource. DarkHydrus' C2 domain 0utl00k[.]net was engineered to resemble Microsoft Outlook's legitimate "outlook.com" domain. For the June 2018 attack, the specific subdomain used matched the name of the targeted educational institution — making the dialog appear to be an internal login prompt — significantly increasing the likelihood of credential submission. Unit42 confirmed DarkHydrus used Phishery by recreating the tool's output and matching the remote template path exactly, then successfully capturing test credentials via the same C2 flow. The use of an open-source tool is consistent with DarkHydrus's broader pattern of leveraging freely available offensive tools rather than developing custom malware.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
SectorEducation
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • 0utl00k[.]net
  • 0b1d5e17443f0896c959d22fa15dadcae5ab083a35b3ff6cb48c7f967649ec82
  • 9eac37a5c675cd1750cd50b01fc05085ce0092a19ba97026292a60b11b45bf49
  • d393349a4ad00902e3d415b622cf27987a0170a786ca3a1f991a521bff645318
  • 107[.]175.150.113
  • 195[.]154.41.150
download

Tip: 6 related IOCs (2 IP, 1 domain, 0 URL, 0 email, 3 file hash) to this threat have been found.

Overlaps

DarkHydrusDarkHydrus Targets Middle Eastern Government with RogueRobin Payloads

Source: Palo Alto Networks - July 2018

Detection (four cases): 0b1d5e17443f0896c959d22fa15dadcae5ab083a35b3ff6cb48c7f967649ec82, 9eac37a5c675cd1750cd50b01fc05085ce0092a19ba97026292a60b11b45bf49, d393349a4ad00902e3d415b622cf27987a0170a786ca3a1f991a521bff645318, 0utl00k[.]net

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: DarkHydrus Credential Harvesting Using Phishery

Palo Alto Unit42 documented a credential harvesting campaign by DarkHydrus targeting government and educational institutions in the Middle East. Attackers sent spearphishing emails with malicious Word documents that, when opened, automatically triggered an authentication prompt asking the user to log in — sending whatever credentials they entered to an attacker-controlled server. The campaign ran from at least September 2017 through June 2018 and used an open-source tool called Phishery to create the malicious documents and capture stolen credentials.

The attacks are attributed to DarkHydrus, a threat group named by Palo Alto Unit42 in July 2018. The group targets Middle Eastern government and academic organizations and is notable for its consistent use of open-source offensive tools rather than custom malware. DarkHydrus is assessed to be an Iranian-linked threat actor based on targeting patterns and infrastructure overlaps with other Iranian-linked groups. This Phishery campaign was discovered in the same period as their RogueRobin backdoor operations against the same target set.

The goal was credential theft — specifically Windows account credentials from employees at targeted Middle Eastern government and educational organizations. Once stolen, these credentials could be used for further access into those organizations' networks, email systems, or internal resources. DarkHydrus did not deploy malware or destructive payloads in this campaign; the entire operation was focused on silently harvesting login credentials through social engineering.

The campaign ran for at least nine months — from September 2017 through June 2018 — targeting government entities and educational institutions in the Middle East. Three separate credential harvesting documents are documented across that period. The targeting is consistent with DarkHydrus's concurrent RogueRobin backdoor operations, suggesting this credential harvesting campaign was one component of a broader, sustained espionage effort against the same target set.

Confirmed targets include government agencies and educational institutions in the Middle East. The June 2018 attack hit an educational institution directly; the September and November 2017 documents appear tailored for specific organizations — the survey decoy and the internal-looking password handover form both suggest the attacker had some familiarity with the target environment. The consistent targeting of both government and academic sectors across this and DarkHydrus's other campaigns indicates these two sectors are the group's primary focus.

The attacker sent a spearphishing email with a malicious Word document. When the victim opened the document, Microsoft Office automatically tried to load a template from a remote URL embedded in the file. This triggered an authentication dialog box — a standard Windows prompt — asking the user to log in. The domain shown in the dialog was designed to look like Outlook.com or the user's own organization. If the user entered their Windows credentials and clicked OK, those credentials were sent directly to the attacker's Phishery C2 server. The document then displayed apparently legitimate-looking content, leaving the victim unaware that anything had happened.

Middle Eastern government and academic organizations hold sensitive information relevant to Iranian state interests — diplomatic communications, research, personnel records, and network credentials that can enable further access. DarkHydrus's use of credential harvesting alongside their RogueRobin backdoor campaigns suggests a two-track approach: stolen credentials for direct network access, and backdoor implants for persistent covert presence. Universities are also targeted as softer entry points — they often have less mature security controls than government ministries while employing researchers and officials with cross-sector access.

Block 0utl00k[.]net and the two C2 IPs in your network perimeter. Disable automatic external template loading in Microsoft Office by configuring Protected View to block remote template requests — this removes the core attack mechanism entirely. Alert on Word documents with external attachedTemplate references in your email gateway or endpoint tooling. Train users to pause before entering credentials into any dialog box that appears when opening an Office document; legitimate services do not use this mechanism. Use the three SHA256 hashes to check email and endpoint logs for historical exposure going back to fall 2017.

About Affiliation
DarkHydrus
DarkHydrus is an Iranian-linked cyber espionage group active since at least 2016, first named by Palo Alto Networks Unit 42. The group targets government agencies and academic institutions primarily across the Middle East using spear phishing with macro-enabled Office documents — including malicious Excel Web Query (.iqy) files — to deliver its custom RogueRobin trojan. RogueRobin is notable for using DNS tunneling as its primary command and control channel, with an optional fallback to the Google Drive API enabling communications to blend into legitimate cloud service traffic. The group also employs AppLocker bypass techniques via regsvr32.exe, sandbox detection, and debugger checks for anti-analysis. Infrastructure overlaps with OilRig and CopyKittens have been noted by researchers, placing DarkHydrus within the broader Iranian state espionage ecosystem. Public reporting on the group is concentrated between 2016 and early 2020.
View DarkHydrus's Insights