DRYHOOK — Malware Profile
DRYHOOK is Python script used to steal credentials. DRYHOOK was first reported in January 2025, and has previously been leveraged by People's Republic of China (PRC) state-affiliated threat actors identified as UNC5221 and SYLVANITE.
MITRE ATT&CK techniques (11)
- T1027.013 Encrypted/Encoded File
- T1056.001 Keylogging
- T1059.006 Python
- T1059.008 Network Device CLI
- T1074.001 Local Data Staging
- T1222.002 Linux and Mac Permissions
- T1489 Service Stop
- T1556 Modify Authentication Process
- T1556.004 Network Device Authentication
- T1601 Modify System Image
- T1685 Disable or Modify Tools