RogueRobin
MITRE ATT&CK: S0270 View on attack.mitre.org
Aliases: RogueRobin
- First seen
- 2018-07-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:53:38
Targeted industries: government-and-public-sector
Targeted regions: country_code:sa
Context
RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#.
Detection coverage
- 498 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Regsvr32 (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Command Obfuscation (attack-pattern)
- Standard Encoding (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Checks (attack-pattern)
- Security Software Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Screen Capture (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Shortcut Modification (attack-pattern)
Used by threat actors
- DarkHydrus (threat-actor)
Reports & references
- researchcenter.paloaltonetworks.com — Unit42 New Threat Actor Group Darkhydrus Targets Middle East Government (report)
- Palo Alto Unit 42 — Darkhydrus Delivers New Trojan That Can Use Google Drive For C2 Communications (report)
- docs.google.com — Edit (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Roguerobin (report)
- ironnet.com — Dns Tunneling Series Part 3 The Siren Song Of Roguerobin (report)
- MITRE ATT&CK — S0270 (report)