HyperBro — Malware Profile
HyperBro is a custom in-memory backdoor used by Threat Group-3390.
MITRE ATT&CK techniques (12)
- T1007 System Service Discovery
- T1027.002 Software Packing
- T1027.013 Encrypted/Encoded File
- T1055 Process Injection
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1113 Screen Capture
- T1140 Deobfuscate/Decode Files or Information
- T1569.002 Service Execution
- T1574.001 DLL
IntelFusions coverage
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16
- German Intelligence Warns APT27 Targeting Businesses with HYPERBRO Malware via Exchange and Zoho Exploits 2026-02-16