Hydraq, also known as 9002 RAT and associated with the Aurora intrusion activity, is a Windows remote-access trojan/backdoor. It provides remote operators with host reconnaissance and control functions, including process monitoring, retrieval of local IP-address information, file reading and deletion, and collection and exfiltration of gathered data. A VNC-derived component can stream a live view of the infected system’s desktop. Hydraq uses encrypted command-and-control communications and can register a service through the Windows Registry; it can later remove that service-registration value during self-uninstallation. The backdoor also permits remote modification and deletion of Registry subkeys.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment. | In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment.
9002 RAT also installed additional malicious tools: an exploit tool for Internet Information Services (IIS) 6 WebDav (exploiting CVE-2017-7269) and an SQL database password dumper. | The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of interest through the update process.
FireEye recently identified another targeted attack campaign that leveraged both the recently announced Internet Explorer zero-day, CVE-2013-1347, as well as recently patched Java exploits CVE-2013-2423 and CVE-2013-1493. ... If a visitor to one of these compromised website was running Internet Explorer 8.0 the malicious javascript would redirect them to a page at www[.]sunshop[.]com[.]tw hosting a CVE-2013-1347 exploit. ... The Internet Explorer (CVE-2013-1347) exploit code pulled down a “9002” RAT from another compromised site at hk[.]sz181[.]com.
The java exploits were packaged as two different jar files. One jar file had a MD5 of f4bee1e845137531f18c226d118e06d7 and exploited CVE-2013-2423. The jar that exploited CVE-2013-2423 dropped a 9002 RAT with a MD5 of d99ed31af1e0ad6fb5bf0f116063e91f. This RAT connected to a command and control server at asp[.]homesvr[.]linkpc[.]net.
The second jar file had a MD5 of 3fbb7321d8610c6e2d990bb25ce34bec and exploited CVE-2013-1493. ... The jar that exploited CVE-2013-1493 dropped a 9002 RAT with a MD5 of 42bd5e7e8f74c15873ff0f4a9ce974cd. ... The exploit site at sunshop[.]com[.]tw previously hosted a different malicious jar file on April 2, 2013. This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat actors associated with Aurora ransomware used Cursor Agent for post-compromise reconnaissance, deployment of NetExec and Nmap, certificate attacks with Certipy, and installation of VPN clients or proxychains. The group also deployed a new Linux ransomware variant targeting VMware ESXi environments.
The operator deployed a Linux variant of the Aurora ransomware, encrypt.out, including an ESXi mode that terminates running VMs and encrypts their VM files.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
In July 2022, Sekoia discovered a new Golang botnet advertised by its alleged developer as Aurora botnet since April 2022... Since September 2022, Aurora malware is advertised as an infostealer... As previously introduced, Aurora is a Golang information stealer.
The installer runs the main stealer payload to extract and exfiltrate sensitive data, including system metadata and Google Chrome master keys from the iCloud Keychain, to the attacker via a Telegram channel named "Aurora," and deploy additional payloads.
The 9002 RAT appears to have been in use since at least 2009 and has historically been used by state-sponsored actors. The malware provides attackers with extensive data exfiltration capabilities. Some variants of 9002 RAT inject into memory and do not write to the disk...
34 distinct techniques documented for this family, organized by ATT&CK tactic.
These fake websites use similar URLs, logos, and branding to convincingly appear legitimate. Once a user visits one of these sites, they’re enticed to download an application containing malware or lured to enter sensitive/personal information into the decoy generated website.
We uncovered Operation Red Signature, an information theft-driven supply chain attack targeting organizations in South Korea. The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of interest through the update process.
To fingerprint the host, Aurora executes three commands on the infected host: wmic os get Caption / wmic path win32_VideoController get name / wmic cpu get name
Exfiltrated data are in JSON format... Cache: content of the stolen file encoded in base64
After checking the vendor IDs, the loader decrypts the final payload in separate chunks and injects it into `sihost.exe` using a process hollowing technique.
The tools ... check for the existence of specific files, windows registry entries ... For example, SIG2 includes System\CurrentControlSet\Control\CrashImage and SIG23 includes software\microsoft\NetWin.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
9002 RAT is the decrypted rcview.log payload, which connects to the command-and-control (C&C) server at 66[.]42[.]37[.]101.
Aurora loader is straightforward, it downloads a remote payload using net_http_Get from the built-in library net/http
The sample was hosted on Cloudflare R2 and copied manually into multiple internal hosts in a victim environment.
The Aurora Linux variant encrypts file contents in place with ChaCha20; in ESXi mode it encrypts VM files including vmdk, vmx, vmsd, vmsn, nvram, vmem, vswp, and log files.
377 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware active since April 2026 that targets organizations globally and operates a data-leak site. Its reported Linux variant targets VMware ESXi environments, encrypting virtual-machine files while preserving hypervisor boot functionality so ransom demands can be displayed.
Linux-based ransomware encryptor targeting VMware ESXi environments. It uses ChaCha20 for file encryption and RSA-4096 for key wrapping; associated activity also includes reconnaissance, credential abuse, NTLM relay, certificate attacks, SQL Server xp_cmdshell execution, DCSync, and S3-based data exfiltration.
Ransomware operation active since April 2026 that conducts post-compromise reconnaissance and exploitation, targets VMware ESXi/vCenter environments, encrypts virtual-machine files, and deliberately skips system volumes so the hypervisor remains bootable and can display the ransom demand.
Cross-platform ransomware with Windows and Linux/ESXi lockers. The Windows payload, sap.exe, removes volume shadow copies, resizes shadow storage, and disables System Restore before encrypting files. Its ESXi mode kills running virtual machines and encrypts virtual-machine files. The operation also uses a Tor negotiation site and ransom note.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.