216.73.217.22

HawkEye Malware: Technical Analysis

· Published 13/11/2024 18:34 · Modified 14/11/2024 08:59

Export JSON

Essential information

Published
13/11/2024 18:34
Modified
14/11/2024 08:59
Tags
2024-11-13 exfiltration hawkeye injection keylogger persistence predatorpain spearphishing stealer
Related entities
4 observables, 2 malware

Description

, also known as , is a long-lived malware that has evolved to include capabilities. Originating before 2010, it gained popularity in 2013 through campaigns. The malware is typically delivered via phishing emails or compromised websites, and utilizes a multi-stage infection process involving file dropping, code , and mechanisms. 's functionality includes keylogging, system information gathering, credential theft, wallet theft, screenshot capture, and security software detection. It can exfiltrate data through various methods and has been used by diverse threat actors, from criminal groups to script kiddies. The malware's versatility and ease of use have contributed to its continued prevalence in cybersecurity incidents.

External references