HawkEye Malware: Technical Analysis
Nov. 14, 2024, 8:59 a.m.
Tags
External References
Description
HawkEye, also known as PredatorPain, is a long-lived keylogger malware that has evolved to include stealer capabilities. Originating before 2010, it gained popularity in 2013 through spearphishing campaigns. The malware is typically delivered via phishing emails or compromised websites, and utilizes a multi-stage infection process involving file dropping, code injection, and persistence mechanisms. HawkEye's functionality includes keylogging, system information gathering, credential theft, wallet theft, screenshot capture, and security software detection. It can exfiltrate data through various methods and has been used by diverse threat actors, from criminal groups to script kiddies. The malware's versatility and ease of use have contributed to its continued prevalence in cybersecurity incidents.
Date
Published: Nov. 13, 2024, 6:34 p.m.
Created: Nov. 13, 2024, 6:34 p.m.
Modified: Nov. 14, 2024, 8:59 a.m.
Indicators
bf20547c930c59781e3da99bfe835489d563d52c281716484e49b1a8384b49a4
ac593f34df2916b3bcea81b7cfd70f28b4633b956717c2942294529ee3010c46
1dacdc296fd6ef6ba817b184cce9901901c47c01d849adfa4222bfabfed61838
890dbc0b99a385173acf639cf13a47544d4041f11ddc0f4df199db6daab9fa86
Attack Patterns
PredatorPain
HawkEye