Hydraq

MITRE ATT&CK: S0203 View on attack.mitre.org

Aliases: Roarur, MdmBot, HomeUnix, Homux, HidraQ, HydraQ, McRat, Aurora, 9002 RAT, HOMEUNIX, Hydraq, McRAT

First seen
2009-01-01 00:00:00
Malware type
rat, trojan
Family
Malware family
Operating systems
windows
Related IoCs
26 (23 malicious)
Last IoC activity
2026-08-28 18:55:55
Profile updated
2026-07-07 15:44:01

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Targeted regions: country_code:us country_code:cn

Context

Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more recent campaigns by other Chinese actors, possibly including APT17.

Recent IoC activity

23 malicious indicators in Maltiverse are attributed to Hydraq (S0203). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-08-28_345fcc0ede1b457987ed7df4a1ec8a92_elex_hive 2026-08-28 1
file sample 2026-08-24_9d084786d9ad5eff9b4982acc9bd71da_frostygoop_glassworm_hive_luca-st... 2026-08-25 1
file sample 2026-08-23_2bea140771f4698ce6708f4b163301b1_aurora_cobalt-strike_coinminer_do... 2026-08-24 1
file sample 2026-08-23_31fb32cbcf03181ff00d793653b3bd29_frostygoop_glassworm_hive_luca-st... 2026-08-24 1
file sample 2026-08-23_55035aab8680f3c94351295cddee7dc3_aurora_cobalt-strike_coinminer_do... 2026-08-24 1
file sample 2026-08-23_561940c5e47b11b87cb4a9d58a3c9f6e_frostygoop_glassworm_hive_luca-st... 2026-08-24 1
file sample 2026-08-23_826f1958eab3a5487cf8faa7ce61e266_aurora_cobalt-strike_coinminer_el... 2026-08-24 1
file sample 2026-08-23_ac4dc1a26d7d13e20c1d3e87d970d28d_aurora_coinminer_dosia_frostygoop... 2026-08-24 1
file sample 2026-08-23_fd468ad27889c217243a864c224474b5_aurora_cobalt-strike_coinminer_do... 2026-08-23 1
file sample 2026-08-22_ce076c01e6b3ff009ed84a7f0ee11bb6_aurora_cobalt-strike_coinminer_do... 2026-08-23 1
file sample 2026-08-21_ef7f8cf7ba710f7d4dd483b6ee7b85ab_frostygoop_glassworm_hive_luca-st... 2026-08-21 1
file sample 2026-08-21_f954f38810012198c94af28b4bc9ca54_aurora_cobalt-strike_coinminer_do... 2026-08-21 1
file sample 2026-08-21_d76d0704dcf58404688016be78078e72_elex_frostygoop_glassworm_hive_sa... 2026-08-21 1
file sample 2026-08-20_1e220537c733b10576340bb86309c25e_elex_frostygoop_glassworm_hive_sa... 2026-08-20 1
file sample 2026-07-06_e6e167eaf1bc7f96fd62fb1f865ebe16_elex_frostygoop_glassworm_hive_sa... 2026-07-06 1
file sample freesofts-tech.zip 2026-07-05 1
file sample 2026-07-05_82f1547ff4df504358dabec4848fc8a7_elex_frostygoop_glassworm_hive_sa... 2026-07-05 1
file sample 2026-03-07_7a3bbb19fbc559e9e8f3faabf2759876_aurora_cobalt-strike_coinminer_do... 2026-03-07 1
file sample 2026-03-06_72343f6c9d136dc7d6e9b0c680a356c6_cobalt-strike_icedid_satacom_vidar 2026-03-06 1
file sample 2026-03-05_9712aeaf38c449d6188cbf33b14d3ae4_coinminer_frostygoop_hive_luca-st... 2026-03-06 1

Detection coverage

  • 4 YARA rules
  • 449 Sigma rules

Malware & tools used

  • Query Registry (attack-pattern)
  • Shared Modules (attack-pattern)
  • Service Execution (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Modify Registry (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Windows Service (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • System Service Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Process Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Exfiltration Over Alternative Protocol (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Access Token Manipulation (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Aurora (yara-rule)
  • SEKOIA_Infostealer_Win_Aurora (yara-rule)
  • SEKOIA_Infostealer_Win_Aurora_Str (yara-rule)
  • MALPEDIA_Win_Aurora_Auto (yara-rule)

Related threat objects

Reports & references

  • paper.seebug.org — Hidden Lynx (report)
  • secureworks.com — Bronze Keystone (report)
  • MITRE ATT&CK — G0001 (report)
  • secureworks.com — Bronze Firestone (report)
  • secureworks.com — Bronze Union (report)
  • secureworks.com — Bronze Express (report)
  • youtube.com — Watch (report)
  • app.box.com — Z1Uanuv1Vn3Vw5Iket1R6Bqrmlra0Gpn (report)
  • Trend Micro — Supply Chain Attack Operation Red Signature Targets South Korean Organizations (report)
  • web.archive.org — Executive Summary Final 1 (report)
  • web.archive.org — The Elderwood Project (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.9002 (report)
  • researchcenter.paloaltonetworks.com — Chinese Actors Use 3102 Malware In Attacks On Us Government And Eu Media (report)
  • infopoint-security.de — The Elderwood Project (report)
  • Trend Micro — Supply Chain Attack Operation Red Signature Targets South Korean Organizations (report)
  • Mandiant — Ready For Summer The Sunshop Campaign (report)
  • Mandiant — Operation Ephemeral Hydra Ie Zero Day Linked To Deputydog Uses Diskless Method (report)
  • Broadcom/Symantec — Webworm Espionage Rats (report)
  • Mandiant — Lady Boyle Comes To Town With A New Exploit (report)
  • Broadcom/Symantec — Elderwood Project 12 En (report)
  • researchcenter.paloaltonetworks.com — Unit 42 Attack Delivers 9002 Trojan Through Google Drive (report)
  • proofpoint.com — Operation Rat Cook Chinese Apt Actors Use Fake Game Thrones Leaks Lures (report)
  • crysys.hu — Ukatemicrysys Territorialdispute (report)
  • tgsoft.it — News Archivio (report)
  • MITRE ATT&CK — S0203 (report)

External references