A cyberespionage group targeting Middle Eastern governments via spearphishing campaigns since at least 2016.
Analyst brief
DarkHydrus, also tracked as LazyMeerkat, is a threat actor operating since at least 2016, primarily targeting government agencies in the Middle East. They gain initial access via spearphishing emails containing password-protected RAR archives with malicious .iqy (Excel Web Query) files. Their key TTPs include Template Injection, PowerShell, RogueRobin and Cobalt Strike for C2, and Mimikatz for credential dumping. Defenders should focus on blocking .iqy file execution, restricting script and macro execution, and monitoring for Cobalt Strike beacon patterns and unauthorized credential access tools.
DarkHydrus
LazyMeerkatG0079Obscure Serpens
unknown
In July 2018, Unit 42 analyzed a targeted attack using a novel file type against at least one government agency in the Middle East. It was carried out by a previously unpublished threat group we track as DarkHydrus. Based on our telemetry, we were able to uncover additional artifacts leading us to believe this adversary group has been in operation with their current playbook since early 2016. This attack diverged from previous attacks we observed from this group as it involved spear-phishing emails sent to targeted organizations with password protected RAR archive attachments that contained malicious Excel Web Query files (.iqy).