Researchers linked multiple phishing-driven campaigns to HawkEye and related surveillance malware, describing a long-running credential-theft threat that targeted organizations across dozens of countries and industries. The malware was delivered through lures such as airline ticket confirmations and fake payment documents, often inside compressed archives or executable attachments, and was also tracked alongside the similar Predator Pain family. Victims included industrial, engineering, manufacturing, government, higher education, retail, telecommunications, and professional services organizations, with especially heavy targeting reported in the United States, Australia, Canada, parts of Asia, and the Middle East.
The malware acted as a feature-rich spyware and keylogger, stealing browser, email, messaging, and FTP credentials, capturing keystrokes, screenshots, clipboard data, and system information, and in some cases injecting into legitimate .NET binaries such as RegAsm.exe and vbc.exe. Investigators said stolen data was exfiltrated through SMTP email, HTTP, PHP web panels, and FTP, including periodic submissions to attacker-controlled mailboxes; one variant checked external connectivity and included the victim’s public IP address in exfiltration messages. Kaspersky also tied Hawkeye-based tooling to Operation Ghoul, a financially motivated spear-phishing operation that hit more than 130 organizations and used both malware delivery and phishing pages to harvest accounts.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos observed sustained malspam campaigns in late 2018 and early 2019 distributing HawkEye Reborn v9 through malicious Office documents exploiting CVE-2017-11882. The campaigns used a heavily obfuscated AutoIT-based infection chain with process hollowing into RegAsm.exe and delivered a credential-stealing .NET payload.
Kaspersky reported another Operation Ghoul wave beginning on June 27, 2016. The attackers continued using spear-phishing emails and HawkEye-based malware to steal credentials, screenshots, keystrokes, and other data.
Kaspersky observed a new wave of Operation Ghoul spear-phishing attacks beginning on June 8, 2016. The campaign heavily targeted industrial, engineering, and manufacturing organizations, with many victims in the United Arab Emirates.
Unit 42 tracked Predator Pain and HawkEye activity during July through September 2015, describing widespread phishing-led surveillance malware campaigns targeting organizations in 80 countries. The report found email was the dominant delivery and exfiltration method, with activity peaking early in the workweek.
Kaspersky said artifacts from Operation Ghoul, including malware and attack-site evidence, showed the campaign had been active since March 2015. The campaign used malware based on commercial HawkEye spyware and targeted organizations for financial gain.
FortiGuard Labs analyzed a new HawkEye variant delivered through a phishing email posing as an airline ticket confirmation and packaged in a 7z archive. The malware used process injection into .NET binaries, logged keystrokes and clipboard data, and exfiltrated stolen information every 10 minutes via SMTP to a Yandex account.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 109 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcesecurelist.com
Open sourcefortinet.com
Open sourceblog.talosintelligence.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.