DEADEYE is a Windows malware family associated with APT41 activity, including intrusions against U.S. state government networks. It has been used as part of multi-stage operations in which the malware is concealed, selectively executed, and launched through native Windows utilities to reduce detection. Reported variants include DEADEYE.EMBED, which can embed payloads inside compiled binaries and in NTFS alternate data streams for defense evasion and staging.
DEADEYE supports execution through living-off-the-land mechanisms, including the use of rundll32.exe and msiexec.exe to launch malicious DLL content. It also incorporates execution guardrails to ensure it runs only on intended victim systems by checking host-specific attributes such as volume serial number, hostname, and DNS domain. This selective execution behavior is consistent with targeted intrusion tradecraft and helps avoid unintended detonation in non-target or analysis environments.
For persistence and stealth, DEADEYE has been observed modifying legitimate scheduled tasks with schtasks /change so that malicious code runs under the guise of normal Windows task activity. It has also been linked to naming conventions intended to blend with legitimate system artifacts. In APT41 operations, DEADEYE components were split into multiple sections on disk as an evasion measure, and the malware family formed part of a broader intrusion set that relied on obfuscation, masquerading, and staged payload delivery.
Overall, DEADEYE is best characterized as a Windows loader used in targeted post-compromise operations, with strong emphasis on embedded payload staging, proxy execution via trusted system binaries, persistence through scheduled task abuse, and defense evasion through filesystem concealment and selective execution controls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
“AppleJeus delivered components using a Windows Installer package (.msi)… executed the 3CXDesktopApp.exe…”, “APT38 has used msiexec.exe to execute malicious files.”, “Rancor has used msiexec to download and execute malicious installer files over HTTP.”, “TA505 has used msiexec to download and execute malicious Windows Installer files.”
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Its DEADEYE.EMBED variant can embed payloads inside a compiled binary.
Its DEADEYE.EMBED variant can embed payloads in a local file's alternate data stream.
A dropper used by APT41, with persistence achieved via modification/abuse of Windows scheduled tasks; binaries were also split into multiple on-disk sections to evade detection.
Variant can embed payloads inside compiled binaries for later execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.