logo

HydroJiin Malware Campaign

ID: 3fd6c12a-e851-5b73-ade6-4b32e54b0d3f

STIX ID: report--3fd6c12a-e851-5b73-ade6-4b32e54b0d3f

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents the "HydroJiin" campaign: an active, multi-stage malware distribution operation run by an actor (aliases Hydro/JiiN) who sells malware on xmr-services.com and leverages pastebin, cracked software lures, and spam to deliver a downloader that chains into NetWiredRC, a Pyrome Python backdoor, socat-based reverse shells, XMRig miner, and QuasarRAT; the report includes detailed infection chain analysis, IoCs (file hashes, URLs, C2 addresses), MITRE ATT&CK mappings, and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.