Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These emails typically contain Microsoft Excel spreadsheets or Microsoft Word documents that leverage CVE-2017-11882, a vulnerability affecting Microsoft Equation Editor. When opened by victims, these malicious documents function as malware downloaders. | Cisco Talos discovered a campaign delivering the HawkEye Reborn keylogger. The loader decrypts HawkEye Reborn v9 (version 9.0.1.6) at runtime and process-hollows it into RegAsm.exe.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Also, the malware seems to inject itself into a remote process due to these API calls
It resolves the addresses of basic API calls by name... resolves the address of the wanted API call by using a custom hash function.
The final malware is packed and coming with its own obfuscation, it is never written to the disk. It's always hidden inside the loader... Decode the malware payload ... stored in SCCJZ resource.
Also, the malware seems to inject itself into a remote process due to these API calls
The next step is starting the legitimate RegAsm.exe process and injecting the decoded data from the resource section via the typical process-hollowing technique.
Decode encoded code from the .data section... Decode the configuration stored in the UDXCUSCK resource... Decode the malware payload ... stored in SCCJZ resource.
The sample executes some anti-analysis checks. This includes a function, which is checking for certain processes by parsing the processlist and comparing the names against a CRC32 checksum.
Collects a plenty of more information: internal & external address, geolocation, installed software, clipboard content, screenshots, passwords and more
159 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A keylogger distributed by campaigns whose loader used the Heaven's Gate technique to evade antivirus detection.
Commodity keylogger/information-stealer delivered via a custom loader that decrypts the payload at runtime and injects it into a legitimate process (RegAsm.exe) using process hollowing; exfiltration observed via attacker-controlled email infrastructure.
A keylogger and information stealer delivered through an anti-analysis loader. The loader keeps the payload encrypted until runtime, establishes persistence through a Startup-folder link, and injects HawkEye into the legitimate RegAsm.exe process via process hollowing. Stolen data is exfiltrated through the specified email account and mail server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.