HIDEDRV

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[HIDEDRV](https://attack.mitre.org/software/S0135) is a rootkit used by [APT28](https://attack.mitre.org/groups/G0007). It has been deployed along with [Downdelph](https://attack.mitre.org/software/S0134) to execute and hide that malware. (Citation: ESET Sednit Part 3) (Citation: Sekoia HideDRV Oct 2016)

Associated Techniques (2)
ID ATT&CK Tactics
T1014 Rootkit -
T1055.001 Dynamic-link Library Injection -
Used by Actors (1)
Metadata
ID: 630
Created: 13/01/2026 17:48
Updated: 07/03/2026 16:00