DRYHOOK
S9013 · Linux, Network Devices
DRYHOOK is Python script used to steal credentials. DRYHOOK was first reported in January 2025, and has previously been leveraged by People's Republic of China (PRC) state-affiliated threat actors identified as UNC5221 and SYLVANITE.
ATT&CK S9013
Sigma rules0
YARA rules0
Live IOCs0