HideDRV is a Windows rootkit associated with APT28, also known as Sofacy, Sednit, and Pawn Storm. It has been documented in the context of APT28’s malware ecosystem and is linked to deployment of the Downdelph implant by injecting a DLL into the explorer.exe process. This behavior indicates use of process injection to execute follow-on malware within a legitimate Windows process, supporting stealth and defense evasion. HideDRV appears in reporting tied to APT28 activity from the mid-2010s and is part of the group’s broader espionage-oriented toolset targeting government, political, defense, and other high-value organizations. High-confidence public characterization supports its role as a rootkit-level component used on Windows systems in support of post-compromise operations and covert payload execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28_2016-10_Sekoia_Rootkit analysisUse case on HideDRV
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that injects a DLL into explorer.exe to execute another payload.
HideDRV is referenced as a rootkit used in an APT28 context, likely for stealth and concealment on compromised Windows systems.
Injects a DLL (for Downdelph) into explorer.exe.
IRON TWILIGHT ... HideDRV ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.