HydraC2 is a DDoS botnet operator active since at least August 2023. It has been linked to prior involvement with the Five Families milieu and has been observed expressing support for the Iranian regime alongside other pro-Iran or aligned disruptive actors. The group is associated with packet-flooding denial-of-service operations, primarily using UDP and at times TCP, to disrupt victim availability rather than conduct covert intrusion or espionage. Reported targeting has included hospitals, aviation, defense, and government entities, particularly in the context of heightened tensions affecting the Middle East. HydraC2 is best characterized as a disruptive actor focused on large-scale service interruption through botnet-enabled DDoS activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.