LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0203: Hydraq

Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more recent campaigns by other Chinese actors, possibly including APT17.[1][2][3][4][5][6][7][8]

EnterpriseS0203MalwareObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Hydraq is a Windows data-theft trojan associated in ATT&CK reporting with Operation Aurora-era activity and later reporting under several names. Its decision value is not just the malware name; it represents a post-compromise capability set that can discover host and network context, collect local data and screen content, maintain or execute through Windows services, manipulate registry and access tokens, transfer tools, encrypt command-and-control traffic, exfiltrate data, and remove evidence.

Executive priority

Treat Hydraq as a useful control-validation case for Windows endpoint resilience and incident readiness. Leaders should ask whether the organization can prove visibility into discovery, persistence, collection, exfiltration, and log-clearing behaviors on high-value Windows systems—not merely whether a signature exists for one malware family. The related group context includes Axiom targeting aerospace, defense, government, manufacturing, and media sectors, so organizations in similar sectors may want to prioritize intelligence review and tabletop response assumptions, while avoiding unsupported claims of current exposure.

Technical view

ATT&CK provides no official detection text for Hydraq, so SOC and detection teams should validate coverage through the related techniques: Windows service creation/modification and service execution, registry query and modification, process/service/system/file discovery, local data collection, screen capture, ingress tool transfer, alternate-protocol exfiltration, symmetric cryptography for C2, file deletion, Windows Event Log clearing, shared module loading, and access token manipulation. Because Hydraq is listed as Windows malware, prioritize Windows endpoint, registry, service-control, process, file, event-log, and network egress telemetry. Correlating multiple behaviors is more defensible than relying on any single indicator or alias.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows service creation, modification, start, and service-control activity
  • Windows Registry query and modification events
  • Windows Event Log clear events and audit-log health signals
  • File creation, deletion, module load, and directory enumeration activity

Detection direction

  • Build detections around behavior clusters mapped to the related ATT&CK techniques rather than the Hydraq name alone.
  • Validate Windows service persistence and execution monitoring, including new or modified services with unusual paths or execution context.
  • Tune registry monitoring for suspicious query/modify patterns while accounting for legitimate administration and software-management noise.
  • Correlate discovery commands or API-driven enumeration with subsequent file access, tool transfer, encrypted outbound traffic, or exfiltration-like flows.
  • Monitor for Windows Event Log clearing and file deletion as potential post-compromise evidence removal; ensure alerting distinguishes authorized maintenance from suspicious clearing.

Mitigation priorities

  • Prioritize hardening and monitoring of high-value Windows endpoints and servers where local data, screenshots, or privileged tokens would create material risk.
  • Restrict administrative permissions and service-management rights to reduce opportunities for service-based persistence, service execution, registry modification, log clearing, and token-related abuse.
  • Maintain reliable endpoint logging, centralized log forwarding, and retention so file deletion or event-log clearing does not eliminate incident evidence.
  • Apply egress control and network monitoring that can identify unusual outbound protocols, destinations, and data-transfer patterns from sensitive systems.
  • Use application control and endpoint protection policies to reduce unauthorized tool transfer, shared-module execution, and unapproved binaries where operationally feasible.
Additional notes and limits

Hydraq has many aliases in the references, including 9002 RAT, HidraQ, HomeUnix, Homux, HydraQ, McRat, MdmBot, Roarur, and others. ATT&CK relationship context links Axiom as using this object and lists numerous techniques used by Hydraq, spanning discovery, collection, execution, persistence, privilege escalation, defense impairment, command and control, and exfiltration. Use those relationships to guide validation, but confirm locally which Windows systems, logs, and network controls provide usable evidence.

The official ATT&CK object does not provide a detection section, labels, aliases in the core alias field, or object-level tactics. Technique relationships provide behavioral context, but the supplied data does not prove active exploitation, current campaign activity, customer exposure, or guaranteed detection coverage. Some related techniques list platforms beyond Windows; Hydraq itself is supplied here as Windows malware, so platform claims should remain Windows-focused unless separate evidence supports more.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Hydraq

Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more recent campaigns by other Chinese actors, possibly including APT17.[1][2][3][4][5][6][7][8]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

19 rows
DomainIDNameRelationship / procedure
EnterpriseT1012Query Registry

Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys.[3][9]

EnterpriseT1129Shared Modules

Hydraq creates a backdoor through which remote attackers can load and call DLL functions.[3][9]

EnterpriseT1569.002Service ExecutionSub-technique

Hydraq uses svchost.exe to execute a malicious DLL included in a new service group.[10]

EnterpriseT1016System Network Configuration Discovery

Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.[3][9]

EnterpriseT1082System Information Discovery

Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed.[9]

EnterpriseT1005Data from Local System

Hydraq creates a backdoor through which remote attackers can read data from files.[3][9]

EnterpriseT1112Modify Registry

Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys.[3][9]

EnterpriseT1105Ingress Tool Transfer

Hydraq creates a backdoor through which remote attackers can download files and additional malware components.[3][9]

EnterpriseT1027Obfuscated Files or Information

Hydraq uses basic obfuscation in the form of spaghetti code.[2][3]

EnterpriseT1543.003Windows ServiceSub-technique

Hydraq creates new services to establish persistence.[3][9][10]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Hydraq creates a backdoor through which remote attackers can clear all system event logs.[3][9]

EnterpriseT1573.001Symmetric CryptographySub-technique

Hydraq C2 traffic is encrypted using bitwise NOT and XOR operations.[9]

EnterpriseT1007System Service Discovery

Hydraq creates a backdoor through which remote attackers can monitor services.[3][9]

EnterpriseT1070.004File DeletionSub-technique

Hydraq creates a backdoor through which remote attackers can delete files.[3][9]

EnterpriseT1057Process Discovery

Hydraq creates a backdoor through which remote attackers can monitor processes.[3][9]

EnterpriseT1113Screen Capture

Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop of an infected host.[9]

EnterpriseT1048Exfiltration Over Alternative Protocol

Hydraq connects to a predefined domain on port 443 to exfil gathered information.[9]

EnterpriseT1083File and Directory Discovery

Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives.[3][9]

EnterpriseT1134Access Token Manipulation

Hydraq creates a backdoor through which remote attackers can adjust token privileges.[9]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0066: Elderwood

Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. [1] The group has targeted defense organizations, supply chain manufacturers, human rights and nongovernmental organizations (NGOs), and IT service providers. [2] [3]

GroupEnterprise

G0001: Axiom

Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.[1][2][3]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
5d64f49a01d24605...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle5d64f49a01d2…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    MicroFocus 9002 Aug 2016

    Petrovsky, O. (2016, August 30). “9002 RAT” -- a second building on the left. Retrieved February 20, 2018.

    Open source URL
  2. [2]
    Symantec Elderwood Sept 2012

    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

    Open source URL
  3. [3]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  4. [4]
    ASERT Seven Pointed Dagger Aug 2015

    ASERT. (2015, August). ASERT Threat Intelligence Report – Uncovering the Seven Pointed Dagger. Retrieved March 19, 2018.

    Open source URL
  5. [5]
    FireEye DeputyDog 9002 November 2013

    Moran, N. et al.. (2013, November 10). Operation Ephemeral Hydra: IE Zero-Day Linked to DeputyDog Uses Diskless Method. Retrieved November 17, 2024.

    Open source URL
  6. [6]
    ProofPoint GoT 9002 Aug 2017

    Huss, D. & Mesa, M. (2017, August 25). Operation RAT Cook: Chinese APT actors use fake Game of Thrones leaks as lures. Retrieved March 19, 2018.

    Open source URL
  7. [7]
    FireEye Sunshop Campaign May 2013

    Moran, N. (2013, May 20). Ready for Summer: The Sunshop Campaign. Retrieved November 17, 2024.

    Open source URL
  8. [8]
    PaloAlto 3102 Sept 2015

    Falcone, R. & Miller-Osborn, J. (2015, September 23). Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media. Retrieved March 19, 2018.

    Open source URL
  9. [9]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  10. [10]
    Symantec Hydraq Persistence Jan 2010

    Fitzgerald, P. (2010, January 26). How Trojan.Hydraq Stays On Your Computer. Retrieved February 22, 2018.

    Open source URL
  11. [11]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  12. [12]
    Cisco Group 72

    Esler, J., Lee, M., and Williams, C. (2014, October 14). Threat Spotlight: Group 72. Retrieved January 14, 2016.

  13. [13]
    9002 RAT

    (Citation: MicroFocus 9002 Aug 2016)

  14. [14]
    9002 RAT

    (Citation: MicroFocus 9002 Aug 2016)

  15. [15]
    9002 RAT

    (Citation: MicroFocus 9002 Aug 2016)

  16. [16]
    ASERT Seven Pointed Dagger Aug 2015

    ASERT. (2015, August). ASERT Threat Intelligence Report – Uncovering the Seven Pointed Dagger. Retrieved March 19, 2018.

    Open source URL
  17. [17]
    ASERT Seven Pointed Dagger Aug 2015

    ASERT. (2015, August). ASERT Threat Intelligence Report – Uncovering the Seven Pointed Dagger. Retrieved March 19, 2018.

    Open source URL
  18. [18]
    Aurora

    (Citation: Symantec Elderwood Sept 2012)(Citation: Symantec Trojan.Hydraq Jan 2010)

  19. [19]
    Aurora

    (Citation: Symantec Elderwood Sept 2012)(Citation: Symantec Trojan.Hydraq Jan 2010)

  20. [20]
    Aurora

    (Citation: Symantec Elderwood Sept 2012)(Citation: Symantec Trojan.Hydraq Jan 2010)

  21. [21]
    FireEye DeputyDog 9002 November 2013

    Moran, N. et al.. (2013, November 10). Operation Ephemeral Hydra: IE Zero-Day Linked to DeputyDog Uses Diskless Method. Retrieved November 17, 2024.

    Open source URL
  22. [22]
    FireEye DeputyDog 9002 November 2013

    Moran, N. et al.. (2013, November 10). Operation Ephemeral Hydra: IE Zero-Day Linked to DeputyDog Uses Diskless Method. Retrieved November 17, 2024.

    Open source URL
  23. [23]
    FireEye Sunshop Campaign May 2013

    Moran, N. (2013, May 20). Ready for Summer: The Sunshop Campaign. Retrieved November 17, 2024.

    Open source URL
  24. [24]
    FireEye Sunshop Campaign May 2013

    Moran, N. (2013, May 20). Ready for Summer: The Sunshop Campaign. Retrieved November 17, 2024.

    Open source URL
  25. [25]
    HidraQ

    (Citation: Novetta-Axiom)

  26. [26]
    HidraQ

    (Citation: Novetta-Axiom)

  27. [27]
    HidraQ

    (Citation: Novetta-Axiom)

  28. [28]
    HomeUnix

    (Citation: Novetta-Axiom)

  29. [29]
    HomeUnix

    (Citation: Novetta-Axiom)

  30. [30]
    HomeUnix

    (Citation: Novetta-Axiom)

  31. [31]
    Homux

    (Citation: Novetta-Axiom)

  32. [32]
    Homux

    (Citation: Novetta-Axiom)

  33. [33]
    Homux

    (Citation: Novetta-Axiom)

  34. [34]
    HydraQ

    (Citation: Novetta-Axiom)

  35. [35]
    HydraQ

    (Citation: Novetta-Axiom)

  36. [36]
    HydraQ

    (Citation: Novetta-Axiom)

  37. [37]
    Hydraq

    (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Trojan.Hydraq Jan 2010)

  38. [38]
    Hydraq

    (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Trojan.Hydraq Jan 2010)

  39. [39]
    Hydraq

    (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Trojan.Hydraq Jan 2010)

  40. [40]
    McRat

    (Citation: Novetta-Axiom)

  41. [41]
    McRat

    (Citation: Novetta-Axiom)

  42. [42]
    McRat

    (Citation: Novetta-Axiom)

  43. [43]
    MdmBot

    (Citation: Novetta-Axiom)

  44. [44]
    MdmBot

    (Citation: Novetta-Axiom)

  45. [45]
    MdmBot

    (Citation: Novetta-Axiom)

  46. [46]
    MicroFocus 9002 Aug 2016

    Petrovsky, O. (2016, August 30). “9002 RAT” -- a second building on the left. Retrieved February 20, 2018.

    Open source URL
  47. [47]
    MicroFocus 9002 Aug 2016

    Petrovsky, O. (2016, August 30). “9002 RAT” -- a second building on the left. Retrieved February 20, 2018.

    Open source URL
  48. [48]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  49. [49]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  50. [50]
    PaloAlto 3102 Sept 2015

    Falcone, R. & Miller-Osborn, J. (2015, September 23). Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media. Retrieved March 19, 2018.

    Open source URL
  51. [51]
    PaloAlto 3102 Sept 2015

    Falcone, R. & Miller-Osborn, J. (2015, September 23). Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media. Retrieved March 19, 2018.

    Open source URL
  52. [52]
    ProofPoint GoT 9002 Aug 2017

    Huss, D. & Mesa, M. (2017, August 25). Operation RAT Cook: Chinese APT actors use fake Game of Thrones leaks as lures. Retrieved March 19, 2018.

    Open source URL
  53. [53]
    ProofPoint GoT 9002 Aug 2017

    Huss, D. & Mesa, M. (2017, August 25). Operation RAT Cook: Chinese APT actors use fake Game of Thrones leaks as lures. Retrieved March 19, 2018.

    Open source URL
  54. [54]
    Roarur

    (Citation: Novetta-Axiom)

  55. [55]
    Roarur

    (Citation: Novetta-Axiom)

  56. [56]
    Roarur

    (Citation: Novetta-Axiom)

  57. [57]
    Symantec Elderwood Sept 2012

    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

    Open source URL
  58. [58]
    Symantec Elderwood Sept 2012

    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

    Open source URL
  59. [59]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  60. [60]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  61. [61]
    mitre-attackS0203
    Open source URL
  62. [62]
    mitre-attackS0203
    Open source URL
  63. [63]
    mitre-attackS0203
    Open source URL
  64. [64]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  65. [65]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  66. [66]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  67. [67]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  68. [68]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  69. [69]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  70. [70]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  71. [71]
    Symantec Hydraq Persistence Jan 2010

    Fitzgerald, P. (2010, January 26). How Trojan.Hydraq Stays On Your Computer. Retrieved February 22, 2018.

    Open source URL
  72. [72]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  73. [73]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  74. [74]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  75. [75]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  76. [76]
    Symantec Elderwood Sept 2012

    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

    Open source URL
  77. [77]
    Symantec Elderwood Sept 2012

    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

    Open source URL
  78. [78]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  79. [79]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  80. [80]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  81. [81]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  82. [82]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  83. [83]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  84. [84]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  85. [85]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  86. [86]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  87. [87]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  88. [88]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  89. [89]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  90. [90]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  91. [91]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  92. [92]
    Symantec Elderwood Sept 2012

    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

    Open source URL
  93. [93]
    Symantec Elderwood Sept 2012

    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

    Open source URL
  94. [94]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  95. [95]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  96. [96]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  97. [97]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  98. [98]
    Symantec Hydraq Persistence Jan 2010

    Fitzgerald, P. (2010, January 26). How Trojan.Hydraq Stays On Your Computer. Retrieved February 22, 2018.

    Open source URL
  99. [99]
    Symantec Hydraq Persistence Jan 2010

    Fitzgerald, P. (2010, January 26). How Trojan.Hydraq Stays On Your Computer. Retrieved February 22, 2018.

    Open source URL
  100. [100]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  101. [101]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  102. [102]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  103. [103]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  104. [104]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  105. [105]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  106. [106]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  107. [107]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  108. [108]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  109. [109]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  110. [110]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  111. [111]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  112. [112]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  113. [113]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  114. [114]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  115. [115]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  116. [116]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  117. [117]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  118. [118]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  119. [119]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  120. [120]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  121. [121]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  122. [122]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  123. [123]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  124. [124]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  125. [125]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  126. [126]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  127. [127]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  128. [128]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  129. [129]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  130. [130]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.