Threat group.View on attack.mitre.org
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
DarkHydrus leveraged PowerShell to download and execute additional scripts for execution. |
| T1187 Forced Authentication |
DarkHydrus used Template Injection to launch an authentication window for users to enter their credentials. |
| T1204.002 Malicious File |
DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded. |
| T1221 Template Injection |
DarkHydrus used an open-source tool, Phishery, to inject malicious remote template URLs into Microsoft Word documents and then sent them to victims to enable Forced Authentication. |
| T1564.003 Hidden Window |
DarkHydrus has used |
| T1566.001 Spearphishing Attachment |
DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server. |
| T1588.002 Tool |
DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.