BlackHawk is an MSIL malware loader observed in the wild and reported by ESET. It uses three layers of obfuscation, with signs that the obfuscation may have been generated using AI tools. The infection chain described in the source material includes a Visual Basic Script and two PowerShell scripts; the second PowerShell stage contains a Base64-encoded BlackHawk loader along with the final payload. BlackHawk has been actively used in spearphishing campaigns to distribute Agent Tesla and has also been used to deliver the Phantom information stealer. Reported targeting includes hundreds of endpoints in Romanian small and medium-sized companies. High-confidence associations in the provided content are limited to these delivery campaigns and ESET’s reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BlackHawk is a loader malware with multiple layers of obfuscation, used to deliver payloads such as Agent Tesla and Phantom stealer. It is notable for using AI-generated code.
BlackHawk is a malware loader used to deliver other payloads, such as AgentTesla, via spearphishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.