Hydraq is a malware-associated threat actor designation linked to the Aurora intrusion activity. It is known in high-confidence reporting primarily through malware behavior and retrospective mapping of intrusion signatures rather than through a richly documented standalone actor profile. Hydraq has been associated with data theft operations and is specifically noted for exfiltrating collected information by connecting to a predefined remote destination over port 443, aligning with exfiltration over an alternative protocol. It has also been linked to the broader Aurora attack cluster in attribution and detection mapping. Based on the available facts, Hydraq is best characterized as an intrusion set or malware-linked actor involved in espionage-oriented collection and exfiltration activity. Publicly supported details in this context do not establish reliable source-country, victim-country, or sector-specific targeting information, nor do they support ransomware or extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a procedure example for exfiltration over an alternative protocol.
Referenced as the likely identity of SIG22, tied to the Aurora intrusion set through registry and driver IoCs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.