DRYHOOK

MITRE ATT&CK: S9013 View on attack.mitre.org

Aliases: DRYHOOK

First seen
2025-01-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
linux, network-devices
Profile updated
2026-07-07 15:29:42

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

DRYHOOK is Python script used to steal credentials. DRYHOOK was first reported in January 2025, and has previously been leveraged by People's Republic of China (PRC) state-affiliated threat actors identified as UNC5221 and SYLVANITE.

Detection coverage

  • 202 Sigma rules

Malware & tools used

  • Linux and Mac Permissions (attack-pattern)
  • Keylogging (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Network Device CLI (attack-pattern)
  • Modify System Image (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Modify Authentication Process (attack-pattern)
  • Python (attack-pattern)
  • Service Stop (attack-pattern)
  • Network Device Authentication (attack-pattern)

Exploited vulnerabilities

  • CVE-2025-22457 (vulnerability)

Reports & references

  • hub.dragos.com — 2026 Yir Executivebriefing%20O G (report)
  • picussecurity.com — Unc5221 Cve 2025 22457 Ivanti Connect Secure (report)
  • MITRE ATT&CK — S9013 (report)
  • cloud.google.com — Ivanti Connect Secure Vpn Zero Day (report)

External references