HawkEye, also known as Predator Pain or PredatorPain, is a long-running commercially marketed Windows credential-stealing malware family commonly characterized as a keylogger. Active since at least 2013, it has been sold through hacking forums and underground markets, including configurable versions such as HawkEye Reborn. It is used by diverse financially motivated operators in opportunistic malspam and targeted spearphishing campaigns, including COVID-19-themed campaigns and Operation Ghoul, which targeted industrial, engineering, manufacturing, shipping, pharmaceutical, technology, and other organizations internationally.
HawkEye logs keystrokes, captures clipboard contents and screenshots, and steals stored credentials and profile data from web browsers, email clients, FTP clients, messaging applications, and other software. Some variants can collect system and security-product information, capture webcam images, and obtain cryptocurrency wallet data. Stolen data may be staged locally and exfiltrated through SMTP, FTP, SFTP, HTTP, or attacker-operated web panels.
Delivery has commonly relied on phishing emails carrying malicious Office documents, compressed archives, or executables, and on links to hosted malicious documents. Observed Office-based chains have exploited CVE-2017-11882. HawkEye has also been distributed through trojanized software and other malware loaders. Variants commonly use obfuscated .NET components, process hollowing or process injection into legitimate Windows and .NET processes, anti-debugging, security-tool interference, self-deletion, and persistence through Windows Run keys or scheduled tasks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
HawkEye is another example of a malware kit that is actively being marketed across various hacking forums. Over the past several months, Talos observed ongoing malware distribution campaigns attempting to leverage the latest version of the HawkEye keylogger/stealer, HawkEye Reborn v9, against organizations to steal sensitive information and account credentials.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection, USB drive infection and others.
This shellcode injects the final payload taken from the resource section into the original RegAsm.exe process.
Then it starts the process-hollowing shellcode, which is stored in the HEXCODE1 variable.
The current version, HawkEye Reborn v9 has been modified from earlier versions and heavily obfuscated to make analysis more difficult.
It concatenates them and uses AES to decrypt the result, using the hardcoded key "pydbdio…"
The e-mails sent by attackers appear to be coming from a bank in the UAE, the Emirates NBD... a quick analysis of the email headers reveals fake sources being utilised to deliver the emails to victims.
This shellcode injects the final payload taken from the resource section into the original RegAsm.exe process.
Then it starts the process-hollowing shellcode, which is stored in the HEXCODE1 variable.
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection
It first sends an HTTP request, http://bot.whatismyipaddress.com , to ask for my machine’s public IP. This is a way to ensure that the victim’s machine is able to access the internet. If it did not reply with a public IP, it stops sending collected data to the email box.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
Version 9 is still using the well-known MailPassView and WebBrowserPassView freeware tools from Nirsoft to steal web and email passwords. | Beside the system information, it steals passwords from common web browsers, Filezilla, Beyluxe Messenger, CoreFTP and the video game "Minecraft."
The adversaries can get detailed information about the victim's machine
The AutoIT script is offering a lot of other functions which are not used in this campaign, like anti-virtual machine detection
It first sends an HTTP request, http://bot.whatismyipaddress.com , to ask for my machine’s public IP. This is a way to ensure that the victim’s machine is able to access the internet. If it did not reply with a public IP, it stops sending collected data to the email box.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
It also starts a keylogger, steals clipboard content, takes screenshots from the desktop and pictures from the webcam.
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing trojan spread via spam messages themed around COVID cures.
Mentioned as another malware sample delivered by the same .NET crypter ecosystem associated with iSpy.
A stealer mentioned as related to M00nD3V in prior reporting.
Infostealer mentioned as one of the families that proliferated after the Zeus source code leak.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.