DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key.45
tool
DRYHOOK S9013
- Type
- malware
- Platforms
- Linux, Network Devices
- Created
- 14 April 2026
- Last modified
- 23 April 2026
DRYHOOK is Python script used to steal credentials. DRYHOOK was first reported in January 2025, and has previously been leveraged by People's Republic of China (PRC) state-affiliated threat actors identified as UNC5221 and SYLVANITE.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S9013
DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device.67
DRYHOOK is a Python-based script that executes within the victim environment.89
DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components.1011
DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location /tmp/cmmmap.kumMW.1213
DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications.1415
Standing S9013
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
51st percentile · 51% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
68th percentile · 68% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
6th percentile · 94% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S9013
386 distinct rules cover the 11 techniques recorded for this tool. The 389 technique-to-rule mappings resolve to 386 distinct rules, because one rule can cover several techniques. 219 Sigma · 167 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org