DarkHydrus

MITRE ATT&CK: G0079 View on attack.mitre.org

Aliases: LazyMeerkat, Obscure Serpens, DarkHydrus

First seen
2016-01-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Last IoC activity
2026-07-17 19:41:56
Profile updated
2026-07-07 11:51:50

Targeted industries: education-and-nonprofits government-and-public-sector

Targeted regions: country_code:ae country_code:sa country_code:jo

Context

DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.

Detection coverage

  • 151 YARA rules
  • 250 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Forced Authentication (attack-pattern)
  • Hidden Window (attack-pattern)
  • PowerShell (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Template Injection (attack-pattern)
  • Tool (attack-pattern)
  • RogueRobin (malware)
  • Cobalt Strike (malware)
  • Mimikatz (malware)

Reports & references

  • pan-unit42.github.io — Playbook Viewer (report)
  • researchcenter.paloaltonetworks.com — Unit42 New Threat Actor Group Darkhydrus Targets Middle East Government (report)
  • mobile.twitter.com — 1083289987339042817 (report)
  • ti.360.net — Latest Target Attack Of Darkhydruns Group Against Middle East En (report)
  • Palo Alto Unit 42 — Unit42 Darkhydrus Uses Phishery Harvest Credentials Middle East (report)
  • Palo Alto Unit 42 — Darkhydrus Delivers New Trojan That Can Use Google Drive For C2 Communications (report)
  • MITRE ATT&CK — G0079 (report)
  • Palo Alto Unit 42 — Obscureserpens (report)

External references