Cisco Talos identified at least three malware-distribution campaigns using loaders that abuse the Heaven’s Gate technique to evade antivirus monitoring before downloading additional payloads. The campaigns delivered the HawkEye Reborn keylogger, the Remcos remote-access trojan, and cryptocurrency-mining malware.
Heaven’s Gate enables a nominally 32-bit process running on 64-bit Windows to escape the WOW64 compatibility layer and execute native 64-bit code, potentially bypassing security tools that do not adequately inspect cross-architecture execution. Windows 10 Control Flow Guard has reduced the technique’s effectiveness, but organizations operating legacy Windows systems remain more exposed to this evasion method.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Sophos identified Heaven’s Gate code in the Emotet trojan during the year of the report.
Malwarebytes observed cryptocurrency-mining malware abusing the Heaven’s Gate technique.
Cisco Talos reported at least three malware-distribution campaigns whose loaders used Heaven’s Gate to evade antivirus detection before installing additional payloads, including HawkEye Reborn, Remcos, and cryptocurrency-mining trojans.
Microsoft introduced Control Flow Guard in Windows 10, which blocked the Heaven’s Gate jump from WOW64 32-bit execution to native 64-bit code.
An anonymous member of the 29A virus-coding group, using the alias Roy G. Biv, documented the Heaven’s Gate technique in the mid-2000s.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 298 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
alex-ionescu.com
Open sourcezdnet.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.