HAWKBALL is a Windows backdoor associated with targeted intrusion activity. It has been delivered through malicious Microsoft Office documents that exploit Equation Editor vulnerabilities including CVE-2017-11882 and CVE-2018-0802, using an OLE object to drop embedded shellcode. Once executed, it performs host reconnaissance by collecting the current username and gathering disk and other system information. It uses Windows API calls for process creation and anti-analysis checks, including debugger detection. HAWKBALL supports remote command execution, including creation of a cmd.exe-based reverse shell, execution of attacker-supplied commands, and return of command output. It also supports file deletion and can exfiltrate system information and files over its command-and-control channel. Its observed functionality is consistent with a compact espionage-oriented backdoor used for post-compromise control, collection, and operator tasking on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...has exploited Office vulnerabilities such as CVE-2017-11882...
...has exploited Microsoft Office vulnerabilities... CVE-2018-0802.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can collect the system username.
Malware that exfiltrates system information and files over its C2 channel.
Malware that uses Windows APIs for process creation, disk reconnaissance, and anti-debugging.
Collects the system username.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.