Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-07

Hyadina

As of 2026-09-08, Hyadina is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ransomware. ATT&CK coverage spans 50 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1046 (Network Service Discovery), T1133 (External Remote Services).

Tracked threats
21 critical · 1 high
First seen
2026-07-09
Last seen
2026-09-08
ATT&CK techniques
50across 2 of 2 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 2 tracked threat(s) · Categories: RANSOMWARE

Activity timeline

Hyadina appears in 2 tracked threats between and ; the busiest month was 2026-07 with 1 report.

ATT&CK techniques observed

50 techniques observed across 2 of 2 tracked threats · Credential Access (9), Stealth (formerly Defense Evasion) (6), Discovery (5), Execution (5), Defense Impairment (4), Impact (4)
  • T1003 OS Credential Dumping — Credential Accessobserved in 2 of 2 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 2 of 2 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 2 of 2 tracked threats
  • T1489 Service Stop — Impactobserved in 2 of 2 tracked threats
  • T1490 Inhibit System Recovery — Impactobserved in 2 of 2 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 2 tracked threats
  • T1003.001 LSASS Memory — Credential Accessobserved in 1 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 2 tracked threats
  • T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 1 of 2 tracked threats

Tracked threats