DarkHydrus
MITRE ATT&CK: G0079 View on attack.mitre.org
Aliases: LazyMeerkat, Obscure Serpens, DarkHydrus
- First seen
- 2016-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- nation-state
- Last IoC activity
- 2026-07-17 19:41:56
- Profile updated
- 2026-07-07 11:51:50
Targeted industries: education-and-nonprofits government-and-public-sector
Targeted regions: country_code:ae country_code:sa country_code:jo
Context
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.
Detection coverage
- 151 YARA rules
- 250 Sigma rules
Malware & tools used
- Malicious File (attack-pattern)
- Forced Authentication (attack-pattern)
- Hidden Window (attack-pattern)
- PowerShell (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Template Injection (attack-pattern)
- Tool (attack-pattern)
- RogueRobin (malware)
- Cobalt Strike (malware)
- Mimikatz (malware)
Reports & references
- pan-unit42.github.io — Playbook Viewer (report)
- researchcenter.paloaltonetworks.com — Unit42 New Threat Actor Group Darkhydrus Targets Middle East Government (report)
- mobile.twitter.com — 1083289987339042817 (report)
- ti.360.net — Latest Target Attack Of Darkhydruns Group Against Middle East En (report)
- Palo Alto Unit 42 — Unit42 Darkhydrus Uses Phishery Harvest Credentials Middle East (report)
- Palo Alto Unit 42 — Darkhydrus Delivers New Trojan That Can Use Google Drive For C2 Communications (report)
- MITRE ATT&CK — G0079 (report)
- Palo Alto Unit 42 — Obscureserpens (report)