HawkEye, also known as Predator Pain or PredatorPain, is a long-running commercially sold credential-stealing malware family for Windows that is commonly categorized as a keylogger but has evolved into a broader infostealer and surveillance trojan. Active since at least the early 2010s, and with reporting that traces its sale and use back even earlier, HawkEye has been marketed on hacking forums and dedicated sales sites, including later variants such as HawkEye Reborn v9. Its broad availability, low cost, and builder-driven customization have made it popular with a wide range of financially motivated operators and opportunistic threat actors.
HawkEye’s core functionality centers on credential theft and user surveillance. Across documented variants, it captures keystrokes, steals clipboard contents, gathers system information, and extracts saved credentials from web browsers, email clients, FTP software, messaging applications, and other desktop applications. Some variants also capture screenshots, collect webcam images, and steal additional application data such as form data or cryptocurrency wallet-related information. Multiple analyses note use of embedded password-recovery utilities and modular components to harvest browser and email credentials.
The malware commonly uses multi-stage execution chains and process injection to evade detection and blend into legitimate activity. Observed variants have used process hollowing or injection into legitimate .NET utilities such as RegAsm.exe and vbc.exe, extracted payload components from resources, and employed obfuscation frameworks including ConfuserEx. Anti-analysis and defense-evasion features reported across samples include anti-debugging checks, security-tool interference, self-deletion, and abuse of Image File Execution Options to impair defensive software. Persistence has been established through Windows Run keys and, in some cases, scheduled tasks.
HawkEye has been distributed primarily through phishing and spearphishing campaigns, often using business-themed lures such as invoices, payment notices, shipping documents, quotations, travel confirmations, and other corporate correspondence. Document-based delivery has included malicious Office files exploiting CVE-2017-11882, as well as compressed archives containing executables. It has also been delivered through loaders, crypters, compromised hosting, and trojanized or fake software. COVID-19-themed spam campaigns also used HawkEye as a payload.
Exfiltration methods vary by build and operator configuration. Documented variants have sent stolen data via SMTP email, FTP, SFTP, HTTP POST, and PHP-based web panels, with some campaigns using periodic automated exfiltration. HawkEye has been used globally across many sectors, including industrial, engineering, manufacturing, transportation, education, government, healthcare-adjacent, and professional services environments. It has featured in financially motivated campaigns such as Operation Ghoul and has also appeared in broader commodity-malware ecosystems alongside loaders, crypters, and other stealers. Its longevity and adaptability have kept it relevant as a widely used credential theft platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
HawkEye is another example of a malware kit that is actively being marketed across various hacking forums. Over the past several months, Talos observed ongoing malware distribution campaigns attempting to leverage the latest version of the HawkEye keylogger/stealer, HawkEye Reborn v9, against organizations to steal sensitive information and account credentials.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection, USB drive infection and others.
This shellcode injects the final payload taken from the resource section into the original RegAsm.exe process.
Then it starts the process-hollowing shellcode, which is stored in the HEXCODE1 variable.
The current version, HawkEye Reborn v9 has been modified from earlier versions and heavily obfuscated to make analysis more difficult.
It concatenates them and uses AES to decrypt the result, using the hardcoded key "pydbdio…"
The e-mails sent by attackers appear to be coming from a bank in the UAE, the Emirates NBD... a quick analysis of the email headers reveals fake sources being utilised to deliver the emails to victims.
This shellcode injects the final payload taken from the resource section into the original RegAsm.exe process.
Then it starts the process-hollowing shellcode, which is stored in the HEXCODE1 variable.
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection
It first sends an HTTP request, http://bot.whatismyipaddress.com , to ask for my machine’s public IP. This is a way to ensure that the victim’s machine is able to access the internet. If it did not reply with a public IP, it stops sending collected data to the email box.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
Version 9 is still using the well-known MailPassView and WebBrowserPassView freeware tools from Nirsoft to steal web and email passwords. | Beside the system information, it steals passwords from common web browsers, Filezilla, Beyluxe Messenger, CoreFTP and the video game "Minecraft."
The adversaries can get detailed information about the victim's machine
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection
It first sends an HTTP request, http://bot.whatismyipaddress.com , to ask for my machine’s public IP. This is a way to ensure that the victim’s machine is able to access the internet. If it did not reply with a public IP, it stops sending collected data to the email box.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing trojan spread via spam messages themed around COVID cures.
Mentioned as another malware sample delivered by the same .NET crypter ecosystem associated with iSpy.
A stealer mentioned as related to M00nD3V in prior reporting.
Infostealer mentioned as one of the families that proliferated after the Zeus source code leak.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.