Hydraq is a Windows remote access trojan also known as HydraQ, 9002 RAT, McRAT, and Naid. It is used in targeted espionage operations to provide remote access, monitor compromised systems, and collect confidential information. It is associated with the Aurora attacks involving exploitation of the Internet Explorer vulnerability CVE-2010-0249.
Hydraq enables operators to monitor running processes, retrieve host IP addresses, read and delete files, and modify or delete Windows Registry subkeys. A component based on VNC code streams a live view of the infected host's desktop. The malware registers a Windows service for persistence and can remove its service registration during uninstallation. It exfiltrates gathered information over port 443 and obfuscates command-and-control traffic using bitwise NOT and XOR operations. Hydraq samples also exhibit memory-injection behavior.
Hydraq has been used by Group 72, also known as Axiom, an espionage actor targeting organizations with valuable intellectual property in manufacturing, industrial, aerospace, defense, and media sectors, particularly in the United States, Japan, Taiwan, and Korea. Hydraq is distinct from the unrelated Aurora ransomware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attack was launched using the malicious Aurora script and targeted the CVE-2010-0249 vulnerability in Microsoft Explorer.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment. | In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment.
9002 RAT also installed additional malicious tools: an exploit tool for Internet Information Services (IIS) 6 WebDav (exploiting CVE-2017-7269) and an SQL database password dumper. | The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of interest through the update process.
FireEye recently identified another targeted attack campaign that leveraged both the recently announced Internet Explorer zero-day, CVE-2013-1347, as well as recently patched Java exploits CVE-2013-2423 and CVE-2013-1493. ... If a visitor to one of these compromised website was running Internet Explorer 8.0 the malicious javascript would redirect them to a page at www[.]sunshop[.]com[.]tw hosting a CVE-2013-1347 exploit. ... The Internet Explorer (CVE-2013-1347) exploit code pulled down a “9002” RAT from another compromised site at hk[.]sz181[.]com.
The java exploits were packaged as two different jar files. One jar file had a MD5 of f4bee1e845137531f18c226d118e06d7 and exploited CVE-2013-2423. The jar that exploited CVE-2013-2423 dropped a 9002 RAT with a MD5 of d99ed31af1e0ad6fb5bf0f116063e91f. This RAT connected to a command and control server at asp[.]homesvr[.]linkpc[.]net.
The second jar file had a MD5 of 3fbb7321d8610c6e2d990bb25ce34bec and exploited CVE-2013-1493. ... The jar that exploited CVE-2013-1493 dropped a 9002 RAT with a MD5 of 42bd5e7e8f74c15873ff0f4a9ce974cd. ... The exploit site at sunshop[.]com[.]tw previously hosted a different malicious jar file on April 2, 2013. This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Similar decompression and relocation shellcodes ... are present in instances of the 9002 RAT malware.
Threat actors associated with Aurora ransomware used Cursor Agent for post-compromise reconnaissance, deployment of NetExec and Nmap, certificate attacks with Certipy, and installation of VPN clients or proxychains. The group also deployed a new Linux ransomware variant targeting VMware ESXi environments.
The operator deployed a Linux variant of the Aurora ransomware, encrypt.out, including an ESXi mode that terminates running VMs and encrypts their VM files.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
In July 2022, Sekoia discovered a new Golang botnet advertised by its alleged developer as Aurora botnet since April 2022... Since September 2022, Aurora malware is advertised as an infostealer... As previously introduced, Aurora is a Golang information stealer.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The Aurora Linux variant encrypts file contents in place with ChaCha20; in ESXi mode it encrypts VM files including vmdk, vmx, vmsd, vmsn, nvram, vmem, vswp, and log files.
377 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
82 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned only as background describing a previous investigation. The content provides no technical details or connection to Azazel's operation.
Ransomware active since April 2026 that targets organizations globally and operates a data-leak site. Its reported Linux variant targets VMware ESXi environments, encrypting virtual-machine files while preserving hypervisor boot functionality so ransom demands can be displayed.
Linux-based ransomware encryptor targeting VMware ESXi environments. It uses ChaCha20 for file encryption and RSA-4096 for key wrapping; associated activity also includes reconnaissance, credential abuse, NTLM relay, certificate attacks, SQL Server xp_cmdshell execution, DCSync, and S3-based data exfiltration.
Ransomware operation active since April 2026 that conducts post-compromise reconnaissance and exploitation, targets VMware ESXi/vCenter environments, encrypts virtual-machine files, and deliberately skips system volumes so the hypervisor remains bootable and can display the ransom demand.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.