Italian investigators tied the EyePyramid cyber-espionage operation to Giulio Occhionero and Francesca Maria Occhionero after uncovering a long-running spear-phishing campaign that compromised prominent figures across Italy’s political, financial, legal, academic, religious, and institutional sectors. Authorities reported more than 100 active victims on the malware server and indications that roughly 16,000 people may have been targeted over several years, with command-and-control evidence placing activity from at least 2014 to 2016 and possible malware development dating back to 2008. The operation reportedly stole tens of gigabytes of data by sending malicious attachments in low-sophistication phishing emails and harvesting files from infected systems.
Technical analysis showed EyePyramid was a .NET implant protected with heavy obfuscation and anti-debugging and anti-virtual-machine checks, while maintaining persistence through Run and RunOnce registry keys. The malware attempted to weaken host defenses by altering firewall rules, changing folder permissions, disabling UAC, and interfering with security tools, then encrypted strings and exfiltrated data with 3DES using host-dependent keys. Stolen data was sent mainly through SMTP and IMAP attachments, with additional WebDAV and HTTP support, and the implant could authenticate to command-and-control servers to download files while also containing code related to Active Directory and LDAP privilege operations.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Italian authorities arrested Giulio Occhionero and Francesca Maria Occhionero as suspects in the EyePyramid espionage operation.
Italian police declassified a court order on a chain of EyePyramid cyberattacks against senior Italian government members and institutions. The order documented more than 100 active victims and indications of roughly 16,000 targets over several years.
Command-and-control evidence cited in the investigation showed the known EyePyramid campaign lasted until August 2016.
Evidence from command-and-control servers indicated the EyePyramid espionage campaign had been active since at least March 2014, targeting prominent Italian figures through spear-phishing emails with malicious attachments.
Researchers identified two initial EyePyramid-related Win32 PE samples via YARA, with compilation timestamps in September 2010 and November 2010.
Securelist reported that the EyePyramid malware may have been developed and possibly used as early as 2008, based on the investigation's findings.
Cisco Talos released a technical analysis of the .NET-based EyePyramid implant, describing its obfuscation, anti-analysis features, persistence mechanisms, defense-evasion behavior, and exfiltration methods.
Securelist published details of the EyePyramid attacks, including command-and-control domains, exfiltration email addresses, sample hashes, phishing lure filenames, and YARA-based identification results for related malware samples.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 218 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.