Hydraq
MITRE ATT&CK: S0203 View on attack.mitre.org
Aliases: Roarur, MdmBot, HomeUnix, Homux, HidraQ, HydraQ, McRat, Aurora, 9002 RAT, HOMEUNIX, Hydraq, McRAT
- First seen
- 2009-01-01 00:00:00
- Malware type
- rat, trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 26 (23 malicious)
- Last IoC activity
- 2026-08-28 18:55:55
- Profile updated
- 2026-07-07 15:44:01
Targeted industries: technology-and-telecommunications government-and-public-sector financial-services
Targeted regions: country_code:us country_code:cn
Context
Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more recent campaigns by other Chinese actors, possibly including APT17.
Recent IoC activity
23 malicious indicators in Maltiverse are attributed to Hydraq (S0203). The 20 most recently updated:
Detection coverage
- 4 YARA rules
- 449 Sigma rules
Malware & tools used
- Query Registry (attack-pattern)
- Shared Modules (attack-pattern)
- Service Execution (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Modify Registry (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Windows Service (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- System Service Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Process Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Exfiltration Over Alternative Protocol (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Access Token Manipulation (attack-pattern)
Used by threat actors
Detection rules
- DITEKSHEN_MALWARE_Win_Aurora (yara-rule)
- SEKOIA_Infostealer_Win_Aurora (yara-rule)
- SEKOIA_Infostealer_Win_Aurora_Str (yara-rule)
- MALPEDIA_Win_Aurora_Auto (yara-rule)
Related threat objects
- Aurora (malware)
Reports & references
- paper.seebug.org — Hidden Lynx (report)
- secureworks.com — Bronze Keystone (report)
- MITRE ATT&CK — G0001 (report)
- secureworks.com — Bronze Firestone (report)
- secureworks.com — Bronze Union (report)
- secureworks.com — Bronze Express (report)
- youtube.com — Watch (report)
- app.box.com — Z1Uanuv1Vn3Vw5Iket1R6Bqrmlra0Gpn (report)
- Trend Micro — Supply Chain Attack Operation Red Signature Targets South Korean Organizations (report)
- web.archive.org — Executive Summary Final 1 (report)
- web.archive.org — The Elderwood Project (report)
- malpedia.caad.fkie.fraunhofer.de — Win.9002 (report)
- researchcenter.paloaltonetworks.com — Chinese Actors Use 3102 Malware In Attacks On Us Government And Eu Media (report)
- infopoint-security.de — The Elderwood Project (report)
- Trend Micro — Supply Chain Attack Operation Red Signature Targets South Korean Organizations (report)
- Mandiant — Ready For Summer The Sunshop Campaign (report)
- Mandiant — Operation Ephemeral Hydra Ie Zero Day Linked To Deputydog Uses Diskless Method (report)
- Broadcom/Symantec — Webworm Espionage Rats (report)
- Mandiant — Lady Boyle Comes To Town With A New Exploit (report)
- Broadcom/Symantec — Elderwood Project 12 En (report)
- researchcenter.paloaltonetworks.com — Unit 42 Attack Delivers 9002 Trojan Through Google Drive (report)
- proofpoint.com — Operation Rat Cook Chinese Apt Actors Use Fake Game Thrones Leaks Lures (report)
- crysys.hu — Ukatemicrysys Territorialdispute (report)
- tgsoft.it — News Archivio (report)
- MITRE ATT&CK — S0203 (report)
External references
- mitre-attack — S0203
- 9002 RAT
- Roarur
- MdmBot
- HomeUnix
- Homux
- HidraQ
- HydraQ
- McRat
- Hydraq
- Aurora
- ASERT Seven Pointed Dagger Aug 2015
- PaloAlto 3102 Sept 2015
- ProofPoint GoT 9002 Aug 2017
- FireEye Sunshop Campaign May 2013
- FireEye DeputyDog 9002 November 2013
- Novetta-Axiom
- Symantec Elderwood Sept 2012
- MicroFocus 9002 Aug 2016
- Symantec Trojan.Hydraq Jan 2010