« All threats

Ransomware groupMITRE S0203

Aurora

Also known as: 9002 rat, hidraq, homeunix, homux, hydraq, mcrat, mdmbot, roarur

[Hydraq](https://attack.mitre.org/software/S0203) is a data-theft trojan first used by [Elderwood](https://attack.mitre.org/groups/G0066) in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more recent campaigns by other Chinese actors, possibly including [APT17](https://attack.mitre.org/groups/G0025).(Citation: MicroFocus 9002 Aug 2016)(Citation: Symantec Elderwood Sept 2012)(Citation: Symantec Trojan.Hydraq Jan 2010)(Citation: ASERT Seven Pointed Dagger Aug 2015)(Citation: FireEye DeputyDog 9002 November 2013)(Citation: ProofPoint GoT 9002 Aug 2017)(Citation: FireEye Sunshop Campaign May 2013)(Citation: PaloAlto 3102 Sept 2015)

Victims in the last 90 days19

Most affected countries

  1. United States9
  2. Germany5
  3. Netherlands2
  4. Austria1
  5. Czechia1
  6. Italy1

Most affected sectors

  1. Technology5
  2. Manufacturing4
  3. Retail4
  4. Transport & logistics2
  5. Construction2
  6. Professional services1
  7. Legal1

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. User Account Management (3 techniques covered)
  2. Restrict File and Directory Permissions (3 techniques covered)
  3. Network Intrusion Prevention (3 techniques covered)
  4. Behavior Prevention on Endpoint (3 techniques covered)
  5. Privileged Account Management (2 techniques covered)
  6. Filter Network Traffic (2 techniques covered)
  7. Audit (2 techniques covered)
  8. Data Loss Prevention (2 techniques covered)

MITRE ATT&CK techniques

Recent victims

OrganisationCountrySectorClaimedStatus
Buford-Thompson Company, LTDUnited StatesConstruction9/30/2026◌ Claimed (unverified)
Benshaw, Inc.United StatesTechnology9/7/2026◌ Claimed (unverified)
Jinny Beauty SupplyUnited StatesRetail9/7/2026◌ Claimed (unverified)
Metrea LLCUnited StatesTechnology9/5/2026◌ Claimed (unverified)
EDIF S.p.A.ItalyRetail9/4/2026◌ Claimed (unverified)
Chip 1 ExchangeGermanyTechnology9/2/2026◌ Claimed (unverified)
Ishbia & Gagleard, P.C.United StatesLegal8/31/2026◌ Claimed (unverified)
SCA Logistik & Fulfillment GmbHGermanyTransport & logistics8/27/2026◌ Claimed (unverified)
ERPIS LLCUnited StatesTechnology8/26/2026◌ Claimed (unverified)
Planungsgruppe M+M AGGermanyProfessional services8/17/2026◌ Claimed (unverified)
Natco Home GroupUnited StatesManufacturing8/17/2026◌ Claimed (unverified)
Lloyd Coils EuropeCzechiaManufacturing8/17/2026◌ Claimed (unverified)
FreywilleAustriaRetail8/11/2026◌ Claimed (unverified)
US Installation Group, Inc.United StatesConstruction8/4/2026◌ Claimed (unverified)
GILDE Handwerk Macrander GmbH & Co. KGGermanyRetail8/4/2026◌ Claimed (unverified)
Van Eijck International Car RescueNetherlandsTransport & logistics7/30/2026◌ Claimed (unverified)
Evosys Laser GmbHGermanyManufacturing7/30/2026◌ Claimed (unverified)
Pyramid Analytics B.V.NetherlandsTechnology7/30/2026◌ Claimed (unverified)
Bretford ManufacturingUnited StatesManufacturing7/29/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.