HydroJiin is a malware operator associated with the aliases Hydro and JiiN and linked to a malware sales operation branded as JiiN shop. The actor has been active since at least 2020 and has run multistage intrusion chains that combine commodity malware, custom tooling, and monetization components. Observed delivery methods include spam-based infection and lures involving cracked software. HydroJiin has used layered payload delivery to deploy multiple malware families and utilities, including NetWire RAT, QuasarRAT, a custom Python backdoor referred to as Pyrome, reverse-shell tooling, and cryptocurrency-mining components based on XMRig. The actor has also used staged downloaders, encoded payload retrieval, and process injection to load malware into legitimate processes. Pyrome supported command-driven download-and-execute behavior and could invoke reverse-shell functionality on both Windows and macOS, indicating cross-platform post-compromise capability. Persistence has been established through autorun mechanisms on Windows. The actor’s operations show a blend of information theft and monetization. NetWire was configured with keylogging enabled, while the broader toolset supported remote access, payload execution, persistence, and cryptocurrency mining. QuasarRAT was also deployed as a later-stage payload. Infrastructure patterns and the operation of a malware storefront advertising products such as a miner, crypter, stealer, and exploit-related tooling indicate an actor involved both in malware-enabled intrusion activity and malware commercialization. Known aliases include Hydro and JiiN. HydroJiin is best characterized as a financially motivated cybercriminal threat actor rather than a nation-state group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a named campaign in which NetWire RAT was detected.
Malware-selling threat actor running the HydroJiin campaign, distributing multiple commodity and custom malware families including infostealers, RATs, a Python backdoor, and miner malware via spam, cracked software lures, Pastebin-hosted payloads, and a dedicated malware e-commerce site.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.