Hydraq — Malware Profile
Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more recent campaigns by other Chinese actors, possibly including APT17.
MITRE ATT&CK techniques (19)
- T1005 Data from Local System
- T1007 System Service Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1027 Obfuscated Files or Information
- T1048 Exfiltration Over Alternative Protocol
- T1057 Process Discovery
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1112 Modify Registry
- T1113 Screen Capture
- T1129 Shared Modules
- T1134 Access Token Manipulation
- T1543.003 Windows Service
- T1569.002 Service Execution
- T1573.001 Symmetric Cryptography
- T1685.005 Clear Windows Event Logs