DarkHydrus Targets Middle Eastern Government with RogueRobin Payloads
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Palo Alto Unit42 introduces DarkHydrus — a previously undisclosed threat group — and documents their July 2018 attack on at least one Middle Eastern government agency using a novel delivery mechanism: malicious Excel Web Query (.iqy) files hidden inside password-protected RAR archives sent via spearphishing. The .iqy file (credential.iqy) contains a single URL pointing to micrrosoft[.]net, which Excel natively fetches on open. The retrieved releasenotes.txt file contains an Excel formula that launches a cmd.exe subprocess to run a PowerShell one-liner, downloading and executing winupdate.ps1 — RogueRobin — from the same server. Both consent dialogs (one for remote data, one for command prompt execution) must be accepted by the user, making social engineering the critical success factor. RogueRobin performs five WMI-based sandbox checks (BIOS version for VBOX/bochs/qemu/virtualbox/vm strings, XEN manufacturer, physical memory <2.9GB, CPU cores ≤1) and enumerates processes for Wireshark and Sysinternals before proceeding. If checks pass, it writes OneDrive.ps1 to %APPDATA% and creates a startup folder shortcut (OneDrive.lnk) for persistence. All C2 communication uses a custom DNS tunneling protocol, testing eight DNS record types (A, AAAA, AC, CNAME, MX, TXT, SRV, SOA) on first run and using the first to receive a response for all subsequent communications. Each DNS query encodes a system ID, job ID, data offset, and base64-encoded data chunk in the subdomain. The eight C2 domains all spoof well-known security vendor brands (Cisco AnyConnect, F5 BIG-IP, Fortiweb, Kaspersky, MikroTik, OWA365, Symantec, Windows Defender). Infrastructure pivoting linked these domains through shared name servers (ns102/ns103.kaspersky[.]host) and revealed overlapping infrastructure with a second DarkHydrus credential harvesting campaign (0utl00k[.]net) and possible Copy Kittens connections (cisc0[.]net, per ClearSky reporting — unconfirmed by Unit42). Unit42 assesses DarkHydrus has been active since at least January 2016 and historically relied on open-source tools (Meterpreter, Cobalt Strike, Empire, Veil, Mimikatz) before pivoting to the custom RogueRobin payload in this campaign.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | Middle East Countries | Verified |
Extracted IOCs
- 0ffice[.]com
- 0ffiice[.]com
- 0utl00k[.]net
- 0utlook[.]bid
- allexa[.]net
- anyconnect[.]stream
- bigip[.]stream
- cisc0[.]net
- fortiweb[.]download
- hotmai1[.]com
- kaspersky[.]host
- kaspersky[.]science
- maccaffe[.]com
- microtik[.]stream
- micrrosoft[.]net
- msdncss[.]com
- owa365[.]bid
- symanteclive[.]download
- windowsdefender[.]win
- 01fd7992aa71f4dca3a3766c438fbabe9aea78ca5812ab75b5371b48bd2625e2
- 0a3d5b2a8ed60e0d96d5f0d9d6e00cd6ab882863afbb951f10c395a3d991fbc1
- 0b1d5e17443f0896c959d22fa15dadcae5ab083a35b3ff6cb48c7f967649ec82
- 26e641a9149ff86759c317b57229f59ac48c5968846813cafb3c4e87c774e245
- 47b8ad55b66cdcd78d972d6df5338b2e32c91af0a666531baf1621d2786e7870
- 6dcb3492a45a08127f9816a1b9e195de2bb7e0731c4e7168392d0e8068adae7a
- 776c056096f0e73898723c0807269bc299ae3bbd8e9542f0a1cbba0fd3470cb4
- 8063c3f134f4413b793dfc05f035b6480aa1636996e8ac4b94646292a5f87fde
- 870c8b29be2b596cc2e33045ec48c80251e668abd736cef9c5449df16cf2d3b8
- 99541ab28fc3328e25723607df4b0d9ea0a1af31b58e2da07eff9f15c4e6565c
- 9eac37a5c675cd1750cd50b01fc05085ce0092a19ba97026292a60b11b45bf49
- a547a02eb4fcb8f446da9b50838503de0d46f9bb2fd197c9ff63021243ea6d88
- ac7f9c536153780ccbec949f23b86f3d16e3105a5f14bb667df752aa815b0dc4
- ad3fd1571277c7ce93dfbd58cee3b3bec84eeaf6bb29a279ecb6a656028f771c
- b2571e3b4afbce56da8faa726b726eb465f2e5e5ed74cf3b172b5dd80460ad81
- b5cfaac25d87a6e8ebabc918facce491788863f120371c9d00009d78b6a8c350
- c8b3d4b6acce6b6655e17255ef7a214651b7fc4e43f9964df24556343393a1a3
- ce84b3c7986e6a48ca3171e703e7083e769e9ced1bbdd7edf8f3eab7ce20fd00
- cec36e8ed65ac6f250c05b4a17c09f58bb80c19b73169aaf40fa15c8d3a9a6a1
- cf7863e023475d695c6f72c471d314b8b1781c6e9087ff4d70118b30205da5f0
- cf9b2b40ac621aaf3241ff570bd7a238f6402102c29e4fbba3c5ce0cb8bc25f9
- d393349a4ad00902e3d415b622cf27987a0170a786ca3a1f991a521bff645318
- d428d79f58425d831c2ee0a73f04749715e8c4dd30ccd81d92fe17485e6dfcda
- dd2625388bb2d2b02b6c10d4ee78f68a918b25ddd712a0862bcf92fa64284ffa
- e88045931b9d99511ce71cc94f2e3d1159581e5eb26d4e05146749e1620dc678
- ff0b59f23630f4a854448b82f1f0cd66bc4b1124a3f49f0aecaca28309673cb0
Tip: 45 related IOCs (0 IP, 19 domain, 0 URL, 0 email, 26 file hash) to this threat have been found.
Overlaps
Source: IronNet - February 2020
Detection (eight cases): anyconnect[.]stream, bigip[.]stream, fortiweb[.]download, kaspersky[.]science, microtik[.]stream, owa365[.]bid, symanteclive[.]download, windowsdefender[.]win
Source: Palo Alto Networks - August 2018
Detection (four cases): 0b1d5e17443f0896c959d22fa15dadcae5ab083a35b3ff6cb48c7f967649ec82, 9eac37a5c675cd1750cd50b01fc05085ce0092a19ba97026292a60b11b45bf49, d393349a4ad00902e3d415b622cf27987a0170a786ca3a1f991a521bff645318, 0utl00k[.]net
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: DarkHydrus — RogueRobin Backdoor and IQY File Delivery
Palo Alto Unit42 named and documented DarkHydrus for the first time, based on a July 2018 attack on at least one Middle Eastern government agency. The group sent Arabic-language spearphishing emails with a password-protected RAR archive. Inside was a malicious Excel Web Query (.iqy) file — an unusual format that Excel automatically processes. When opened, it triggered a two-step download chain that ultimately installed RogueRobin, a custom PowerShell backdoor the group appears to have developed themselves — a shift from their previous reliance on off-the-shelf tools like Cobalt Strike and Meterpreter.
The attack is attributed to DarkHydrus, a threat group Unit42 tracks and named in this report. DarkHydrus is assessed to be an Iranian-linked cyberespionage group that has been active since at least January 2016. Infrastructure pivoting linked the group's C2 domains to possible overlap with Copy Kittens (per ClearSky), though Unit42 found insufficient technical evidence to confirm a connection. DarkHydrus is notable for its consistent targeting of Middle Eastern government and academic institutions and its evolution from open-source tools to custom malware.
The goal was espionage. RogueRobin gives DarkHydrus persistent covert access to compromised government machines — operators can run arbitrary PowerShell commands, upload and download files, capture screenshots, and adjust C2 behavior. The custom DNS tunneling C2 channel blends traffic with normal DNS queries, making detection significantly harder than HTTP-based C2. The pivot from open-source tools to a custom payload in this campaign suggests the group was investing in longer-term, harder-to-attribute capabilities.
The July 2018 attack targeted at least one Middle Eastern government agency. Unit42's campaign analysis identified DarkHydrus infrastructure and payloads dating back to January 2016, suggesting sustained operations across multiple targets over more than two years. The same C2 infrastructure overlapped with a parallel DarkHydrus credential harvesting campaign running from September 2017 through June 2018. Oldest known C2 domain (micrrosoft[.]net) was reused across three separate payload generations.
Confirmed targets were government agencies in the Middle East. Unit42's broader DarkHydrus reporting also documents attacks on educational institutions. The consistent focus on these two sectors across multiple years and campaigns is DarkHydrus's defining targeting characteristic — consistent with intelligence collection objectives against organizations that hold political, diplomatic, and institutional information of value to Iranian state interests.
A spearphishing email in Arabic delivered a password-protected RAR archive containing a .iqy file. Opening the .iqy file in Excel triggered the first consent dialog — Excel asking permission to download remote data. If approved, Excel fetched a file from the attacker's server containing a formula that launched cmd.exe — triggering a second consent dialog. If that was also approved, a PowerShell script (RogueRobin) was downloaded and executed. Before doing anything further, RogueRobin ran five checks to detect sandbox environments via WMI queries. If none were detected, it copied itself to %APPDATA% under an OneDrive name and created a startup shortcut for persistence. It then began communicating with attacker-controlled C2 servers exclusively through DNS queries, using whichever of 8 DNS record types received a response first.
Middle Eastern government agencies hold diplomatic communications, policy information, and personnel records of direct value to Iranian state intelligence. DarkHydrus has shown consistent, multi-year interest in these organizations. The .iqy delivery method is also notable for its obscurity — it's a legitimate Excel feature rarely used in enterprise environments, meaning most email security filters and user awareness training wouldn't flag it, giving the attacker a higher probability of a successful consent click-through.
Restrict Excel's ability to load remote data from .iqy files via Group Policy — this blocks the entire delivery chain without requiring any other detection. Alert on cmd.exe processes spawned from Excel with PowerShell download-and-execute command lines. Block all eight C2 domains in the IOC bundle and monitor DNS traffic for the RogueRobin subdomain pattern. Hunt for OneDrive.lnk in Windows startup folders and OneDrive.ps1 in %APPDATA% with unexpected content. Enable PowerShell script block logging so that Invoke-Obfuscation COMPRESS payloads are captured in memory at decompression time, even if not written to disk in readable form.