Hydraq, also widely associated with the Aurora intrusion activity and sometimes referred to as 9002 RAT, is a Windows backdoor used in targeted espionage operations. It is known for providing remote operators with persistent access to compromised systems and a range of surveillance and host-management functions. Reported capabilities include monitoring running processes, retrieving host network information such as IP addresses, reading and deleting files, modifying and deleting Windows Registry subkeys, and uninstalling itself by removing its service-related Registry data. Hydraq also includes a VNC-derived component that can stream a live view of the victim desktop, giving operators interactive visibility into user activity.
Hydraq communicates with command-and-control infrastructure using encrypted traffic that has been described as obfuscated with simple bitwise operations, and it has been observed exfiltrating collected information over port 443. The malware has been linked to the Aurora attacks and has appeared in reporting on Chinese espionage activity. It has also been associated in some reporting with clusters or tooling names such as McRAT and with later supply-chain delivery of 9002 RAT in targeted intrusions against organizations of interest. The malware is primarily a remote access implant rather than a commodity stealer or ransomware family.
Victimology in public reporting centers on targeted enterprise and government environments, especially in espionage contexts. Its functionality supports post-compromise surveillance, data theft, and long-term access on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment. | In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment.
9002 RAT also installed additional malicious tools: an exploit tool for Internet Information Services (IIS) 6 WebDav (exploiting CVE-2017-7269) and an SQL database password dumper. | The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of interest through the update process.
FireEye recently identified another targeted attack campaign that leveraged both the recently announced Internet Explorer zero-day, CVE-2013-1347, as well as recently patched Java exploits CVE-2013-2423 and CVE-2013-1493. ... If a visitor to one of these compromised website was running Internet Explorer 8.0 the malicious javascript would redirect them to a page at www[.]sunshop[.]com[.]tw hosting a CVE-2013-1347 exploit. ... The Internet Explorer (CVE-2013-1347) exploit code pulled down a “9002” RAT from another compromised site at hk[.]sz181[.]com.
The java exploits were packaged as two different jar files. One jar file had a MD5 of f4bee1e845137531f18c226d118e06d7 and exploited CVE-2013-2423. The jar that exploited CVE-2013-2423 dropped a 9002 RAT with a MD5 of d99ed31af1e0ad6fb5bf0f116063e91f. This RAT connected to a command and control server at asp[.]homesvr[.]linkpc[.]net.
The second jar file had a MD5 of 3fbb7321d8610c6e2d990bb25ce34bec and exploited CVE-2013-1493. ... The jar that exploited CVE-2013-1493 dropped a 9002 RAT with a MD5 of 42bd5e7e8f74c15873ff0f4a9ce974cd. ... The exploit site at sunshop[.]com[.]tw previously hosted a different malicious jar file on April 2, 2013. This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
In July 2022, Sekoia discovered a new Golang botnet advertised by its alleged developer as Aurora botnet since April 2022... Since September 2022, Aurora malware is advertised as an infostealer... As previously introduced, Aurora is a Golang information stealer.
The installer runs the main stealer payload to extract and exfiltrate sensitive data, including system metadata and Google Chrome master keys from the iCloud Keychain, to the attacker via a Telegram channel named "Aurora," and deploy additional payloads.
The 9002 RAT appears to have been in use since at least 2009 and has historically been used by state-sponsored actors. The malware provides attackers with extensive data exfiltration capabilities. Some variants of 9002 RAT inject into memory and do not write to the disk...
The 9002 RAT appears to have been in use since at least 2009 and has historically been used by state-sponsored actors. The malware provides attackers with extensive data exfiltration capabilities. Some variants of 9002 RAT inject into memory and do not write to the disk...
38 distinct techniques documented for this family, organized by ATT&CK tactic.
These fake websites use similar URLs, logos, and branding to convincingly appear legitimate. Once a user visits one of these sites, they’re enticed to download an application containing malware or lured to enter sensitive/personal information into the decoy generated website.
We uncovered Operation Red Signature, an information theft-driven supply chain attack targeting organizations in South Korea. The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of interest through the update process.
To fingerprint the host, Aurora executes three commands on the infected host: wmic os get Caption / wmic path win32_VideoController get name / wmic cpu get name
This dynamic-link library (DLL) is responsible for decrypting the encrypted rcview.log file and executing it in memory.
After checking the vendor IDs, the loader decrypts the final payload in separate chunks and injects it into `sihost.exe` using a process hollowing technique.
Exfiltrated data are in JSON format... Cache: content of the stolen file encoded in base64
After checking the vendor IDs, the loader decrypts the final payload in separate chunks and injects it into `sihost.exe` using a process hollowing technique.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
FileName: name of the stolen file ( e.g. cookies.sqlite, Login Data)
The tools ... check for the existence of specific files, windows registry entries ... For example, SIG2 includes System\CurrentControlSet\Control\CrashImage and SIG23 includes software\microsoft\NetWin.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
9002 RAT is the decrypted rcview.log payload, which connects to the command-and-control (C&C) server at 66[.]42[.]37[.]101.
Aurora loader is straightforward, it downloads a remote payload using net_http_Get from the built-in library net/http
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
if a file name matches the stealer logic, the file is encoded in base64 and sent to the C2
377 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
72 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware brand newly appearing in industrial victim claims in Q2 2026.
A Golang multi-purpose malware family that evolved from a MaaS-advertised botnet into a prevalent infostealer. It fingerprints infected Windows hosts via WMIC, captures screenshots, steals data from browsers, cryptocurrency wallet extensions and desktop wallets, grabs selected files, exfiltrates data to C2 over TCP/JSON, and can download and execute next-stage payloads via PowerShell.
A stealer payload used in the macOS kill chain to extract and exfiltrate sensitive data, including system metadata and Chrome master keys from iCloud Keychain, and to deploy additional payloads.
A long-used remote access trojan with extensive data exfiltration capabilities. Some variants are memory-injected and diskless. In the Webworm case, the group modified the malware’s communication protocol and encryption to evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.