Threats Feed|DarkHydrus|Last Updated 29/04/2026|AuthorCertfa Radar|Publish Date27/07/2018

DarkHydrus Targets Middle Eastern Government with RogueRobin Payloads

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Palo Alto Unit42 introduces DarkHydrus — a previously undisclosed threat group — and documents their July 2018 attack on at least one Middle Eastern government agency using a novel delivery mechanism: malicious Excel Web Query (.iqy) files hidden inside password-protected RAR archives sent via spearphishing. The .iqy file (credential.iqy) contains a single URL pointing to micrrosoft[.]net, which Excel natively fetches on open. The retrieved releasenotes.txt file contains an Excel formula that launches a cmd.exe subprocess to run a PowerShell one-liner, downloading and executing winupdate.ps1 — RogueRobin — from the same server. Both consent dialogs (one for remote data, one for command prompt execution) must be accepted by the user, making social engineering the critical success factor. RogueRobin performs five WMI-based sandbox checks (BIOS version for VBOX/bochs/qemu/virtualbox/vm strings, XEN manufacturer, physical memory <2.9GB, CPU cores ≤1) and enumerates processes for Wireshark and Sysinternals before proceeding. If checks pass, it writes OneDrive.ps1 to %APPDATA% and creates a startup folder shortcut (OneDrive.lnk) for persistence. All C2 communication uses a custom DNS tunneling protocol, testing eight DNS record types (A, AAAA, AC, CNAME, MX, TXT, SRV, SOA) on first run and using the first to receive a response for all subsequent communications. Each DNS query encodes a system ID, job ID, data offset, and base64-encoded data chunk in the subdomain. The eight C2 domains all spoof well-known security vendor brands (Cisco AnyConnect, F5 BIG-IP, Fortiweb, Kaspersky, MikroTik, OWA365, Symantec, Windows Defender). Infrastructure pivoting linked these domains through shared name servers (ns102/ns103.kaspersky[.]host) and revealed overlapping infrastructure with a second DarkHydrus credential harvesting campaign (0utl00k[.]net) and possible Copy Kittens connections (cisc0[.]net, per ClearSky reporting — unconfirmed by Unit42). Unit42 assesses DarkHydrus has been active since at least January 2016 and historically relied on open-source tools (Meterpreter, Cobalt Strike, Empire, Veil, Mimikatz) before pivoting to the custom RogueRobin payload in this campaign.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • 0ffice[.]com
  • 0ffiice[.]com
  • 0utl00k[.]net
  • 0utlook[.]bid
  • allexa[.]net
  • anyconnect[.]stream
  • bigip[.]stream
  • cisc0[.]net
  • fortiweb[.]download
  • hotmai1[.]com
  • kaspersky[.]host
  • kaspersky[.]science
  • maccaffe[.]com
  • microtik[.]stream
  • micrrosoft[.]net
  • msdncss[.]com
  • owa365[.]bid
  • symanteclive[.]download
  • windowsdefender[.]win
  • 01fd7992aa71f4dca3a3766c438fbabe9aea78ca5812ab75b5371b48bd2625e2
  • 0a3d5b2a8ed60e0d96d5f0d9d6e00cd6ab882863afbb951f10c395a3d991fbc1
  • 0b1d5e17443f0896c959d22fa15dadcae5ab083a35b3ff6cb48c7f967649ec82
  • 26e641a9149ff86759c317b57229f59ac48c5968846813cafb3c4e87c774e245
  • 47b8ad55b66cdcd78d972d6df5338b2e32c91af0a666531baf1621d2786e7870
  • 6dcb3492a45a08127f9816a1b9e195de2bb7e0731c4e7168392d0e8068adae7a
  • 776c056096f0e73898723c0807269bc299ae3bbd8e9542f0a1cbba0fd3470cb4
  • 8063c3f134f4413b793dfc05f035b6480aa1636996e8ac4b94646292a5f87fde
  • 870c8b29be2b596cc2e33045ec48c80251e668abd736cef9c5449df16cf2d3b8
  • 99541ab28fc3328e25723607df4b0d9ea0a1af31b58e2da07eff9f15c4e6565c
  • 9eac37a5c675cd1750cd50b01fc05085ce0092a19ba97026292a60b11b45bf49
  • a547a02eb4fcb8f446da9b50838503de0d46f9bb2fd197c9ff63021243ea6d88
  • ac7f9c536153780ccbec949f23b86f3d16e3105a5f14bb667df752aa815b0dc4
  • ad3fd1571277c7ce93dfbd58cee3b3bec84eeaf6bb29a279ecb6a656028f771c
  • b2571e3b4afbce56da8faa726b726eb465f2e5e5ed74cf3b172b5dd80460ad81
  • b5cfaac25d87a6e8ebabc918facce491788863f120371c9d00009d78b6a8c350
  • c8b3d4b6acce6b6655e17255ef7a214651b7fc4e43f9964df24556343393a1a3
  • ce84b3c7986e6a48ca3171e703e7083e769e9ced1bbdd7edf8f3eab7ce20fd00
  • cec36e8ed65ac6f250c05b4a17c09f58bb80c19b73169aaf40fa15c8d3a9a6a1
  • cf7863e023475d695c6f72c471d314b8b1781c6e9087ff4d70118b30205da5f0
  • cf9b2b40ac621aaf3241ff570bd7a238f6402102c29e4fbba3c5ce0cb8bc25f9
  • d393349a4ad00902e3d415b622cf27987a0170a786ca3a1f991a521bff645318
  • d428d79f58425d831c2ee0a73f04749715e8c4dd30ccd81d92fe17485e6dfcda
  • dd2625388bb2d2b02b6c10d4ee78f68a918b25ddd712a0862bcf92fa64284ffa
  • e88045931b9d99511ce71cc94f2e3d1159581e5eb26d4e05146749e1620dc678
  • ff0b59f23630f4a854448b82f1f0cd66bc4b1124a3f49f0aecaca28309673cb0
download

Tip: 45 related IOCs (0 IP, 19 domain, 0 URL, 0 email, 26 file hash) to this threat have been found.

Overlaps

DarkHydrusRogueRobin DNS Tunneling: A Look at DarkHydrus' Cyber Espionage Tactics

Source: IronNet - February 2020

Detection (eight cases): anyconnect[.]stream, bigip[.]stream, fortiweb[.]download, kaspersky[.]science, microtik[.]stream, owa365[.]bid, symanteclive[.]download, windowsdefender[.]win

DarkHydrusDarkHydrus Exploits Open-Source Tools in Cyberattacks Against Middle Eastern Governments and Academia

Source: Palo Alto Networks - August 2018

Detection (four cases): 0b1d5e17443f0896c959d22fa15dadcae5ab083a35b3ff6cb48c7f967649ec82, 9eac37a5c675cd1750cd50b01fc05085ce0092a19ba97026292a60b11b45bf49, d393349a4ad00902e3d415b622cf27987a0170a786ca3a1f991a521bff645318, 0utl00k[.]net

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: DarkHydrus — RogueRobin Backdoor and IQY File Delivery

Palo Alto Unit42 named and documented DarkHydrus for the first time, based on a July 2018 attack on at least one Middle Eastern government agency. The group sent Arabic-language spearphishing emails with a password-protected RAR archive. Inside was a malicious Excel Web Query (.iqy) file — an unusual format that Excel automatically processes. When opened, it triggered a two-step download chain that ultimately installed RogueRobin, a custom PowerShell backdoor the group appears to have developed themselves — a shift from their previous reliance on off-the-shelf tools like Cobalt Strike and Meterpreter.

The attack is attributed to DarkHydrus, a threat group Unit42 tracks and named in this report. DarkHydrus is assessed to be an Iranian-linked cyberespionage group that has been active since at least January 2016. Infrastructure pivoting linked the group's C2 domains to possible overlap with Copy Kittens (per ClearSky), though Unit42 found insufficient technical evidence to confirm a connection. DarkHydrus is notable for its consistent targeting of Middle Eastern government and academic institutions and its evolution from open-source tools to custom malware.

The goal was espionage. RogueRobin gives DarkHydrus persistent covert access to compromised government machines — operators can run arbitrary PowerShell commands, upload and download files, capture screenshots, and adjust C2 behavior. The custom DNS tunneling C2 channel blends traffic with normal DNS queries, making detection significantly harder than HTTP-based C2. The pivot from open-source tools to a custom payload in this campaign suggests the group was investing in longer-term, harder-to-attribute capabilities.

The July 2018 attack targeted at least one Middle Eastern government agency. Unit42's campaign analysis identified DarkHydrus infrastructure and payloads dating back to January 2016, suggesting sustained operations across multiple targets over more than two years. The same C2 infrastructure overlapped with a parallel DarkHydrus credential harvesting campaign running from September 2017 through June 2018. Oldest known C2 domain (micrrosoft[.]net) was reused across three separate payload generations.

Confirmed targets were government agencies in the Middle East. Unit42's broader DarkHydrus reporting also documents attacks on educational institutions. The consistent focus on these two sectors across multiple years and campaigns is DarkHydrus's defining targeting characteristic — consistent with intelligence collection objectives against organizations that hold political, diplomatic, and institutional information of value to Iranian state interests.

A spearphishing email in Arabic delivered a password-protected RAR archive containing a .iqy file. Opening the .iqy file in Excel triggered the first consent dialog — Excel asking permission to download remote data. If approved, Excel fetched a file from the attacker's server containing a formula that launched cmd.exe — triggering a second consent dialog. If that was also approved, a PowerShell script (RogueRobin) was downloaded and executed. Before doing anything further, RogueRobin ran five checks to detect sandbox environments via WMI queries. If none were detected, it copied itself to %APPDATA% under an OneDrive name and created a startup shortcut for persistence. It then began communicating with attacker-controlled C2 servers exclusively through DNS queries, using whichever of 8 DNS record types received a response first.

Middle Eastern government agencies hold diplomatic communications, policy information, and personnel records of direct value to Iranian state intelligence. DarkHydrus has shown consistent, multi-year interest in these organizations. The .iqy delivery method is also notable for its obscurity — it's a legitimate Excel feature rarely used in enterprise environments, meaning most email security filters and user awareness training wouldn't flag it, giving the attacker a higher probability of a successful consent click-through.

Restrict Excel's ability to load remote data from .iqy files via Group Policy — this blocks the entire delivery chain without requiring any other detection. Alert on cmd.exe processes spawned from Excel with PowerShell download-and-execute command lines. Block all eight C2 domains in the IOC bundle and monitor DNS traffic for the RogueRobin subdomain pattern. Hunt for OneDrive.lnk in Windows startup folders and OneDrive.ps1 in %APPDATA% with unexpected content. Enable PowerShell script block logging so that Invoke-Obfuscation COMPRESS payloads are captured in memory at decompression time, even if not written to disk in readable form.

About Affiliation
DarkHydrus
DarkHydrus is an Iranian-linked cyber espionage group active since at least 2016, first named by Palo Alto Networks Unit 42. The group targets government agencies and academic institutions primarily across the Middle East using spear phishing with macro-enabled Office documents — including malicious Excel Web Query (.iqy) files — to deliver its custom RogueRobin trojan. RogueRobin is notable for using DNS tunneling as its primary command and control channel, with an optional fallback to the Google Drive API enabling communications to blend into legitimate cloud service traffic. The group also employs AppLocker bypass techniques via regsvr32.exe, sandbox detection, and debugger checks for anti-analysis. Infrastructure overlaps with OilRig and CopyKittens have been noted by researchers, placing DarkHydrus within the broader Iranian state espionage ecosystem. Public reporting on the group is concentrated between 2016 and early 2020.
View DarkHydrus's Insights