DRYHOOK — Malware Profile

DRYHOOK is Python script used to steal credentials. DRYHOOK was first reported in January 2025, and has previously been leveraged by People's Republic of China (PRC) state-affiliated threat actors identified as UNC5221 and SYLVANITE.

MITRE ATT&CK techniques (11)

Exploited vulnerabilities

Read the full analysis on IntelFusions