HawkEye is a commercially distributed Windows information stealer and keylogger sold through hacking forums and public-facing websites since at least 2013. It is used by multiple independent threat actors, particularly financially motivated cybercriminals, to steal account credentials and sensitive business information. The family has undergone continuing development and ownership changes, with HawkEye Reborn v9 marketed through tiered licenses that included software updates. Builder-configurable features produce substantial variation between samples.
HawkEye records keystrokes and clipboard contents, extracts saved credentials from web browsers, email clients, FTP clients, messaging applications, and other software, and collects system information. It can also capture screenshots and webcam images. Some versions embed NirSoft credential-recovery utilities. Supported exfiltration channels include email, FTP, SFTP, and HTTP-based web panels. Observed variants establish persistence through Windows startup registry entries or scheduled tasks, use process injection and process hollowing to execute within legitimate .NET utilities, and employ obfuscation, encrypted resources, anti-debugging checks, and security-application interference to hinder detection and analysis.
Distribution primarily involves phishing and malspam using business-themed lures such as invoices, purchase orders, payment notifications, and shipping documents; airline-ticket and COVID-19-themed campaigns have also been observed. Delivery chains include compressed executable attachments, malicious links, and weaponized Office documents, including documents exploiting CVE-2017-11882. HawkEye-based malware was used in Operation Ghoul against industrial, engineering, and manufacturing organizations, particularly in the Middle East. Other campaigns have targeted organizations worldwide across technology, education, transportation, retail, professional services, and government. Stolen credentials and correspondence can support business email compromise and supply-chain payment fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
HawkEye is another example of a malware kit that is actively being marketed across various hacking forums. Over the past several months, Talos observed ongoing malware distribution campaigns attempting to leverage the latest version of the HawkEye keylogger/stealer, HawkEye Reborn v9, against organizations to steal sensitive information and account credentials.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection, USB drive infection and others.
This shellcode injects the final payload taken from the resource section into the original RegAsm.exe process.
Then it starts the process-hollowing shellcode, which is stored in the HEXCODE1 variable.
The current version, HawkEye Reborn v9 has been modified from earlier versions and heavily obfuscated to make analysis more difficult.
It concatenates them and uses AES to decrypt the result, using the hardcoded key "pydbdio…"
The e-mails sent by attackers appear to be coming from a bank in the UAE, the Emirates NBD... a quick analysis of the email headers reveals fake sources being utilised to deliver the emails to victims.
This shellcode injects the final payload taken from the resource section into the original RegAsm.exe process.
Then it starts the process-hollowing shellcode, which is stored in the HEXCODE1 variable.
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection
It first sends an HTTP request, http://bot.whatismyipaddress.com , to ask for my machine’s public IP. This is a way to ensure that the victim’s machine is able to access the internet. If it did not reply with a public IP, it stops sending collected data to the email box.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
Version 9 is still using the well-known MailPassView and WebBrowserPassView freeware tools from Nirsoft to steal web and email passwords. | Beside the system information, it steals passwords from common web browsers, Filezilla, Beyluxe Messenger, CoreFTP and the video game "Minecraft."
The adversaries can get detailed information about the victim's machine
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection
It first sends an HTTP request, http://bot.whatismyipaddress.com , to ask for my machine’s public IP. This is a way to ensure that the victim’s machine is able to access the internet. If it did not reply with a public IP, it stops sending collected data to the email box.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing trojan spread via spam messages themed around COVID cures.
Mentioned as another malware sample delivered by the same .NET crypter ecosystem associated with iSpy.
A stealer mentioned as related to M00nD3V in prior reporting.
Infostealer mentioned as one of the families that proliferated after the Zeus source code leak.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.