Last seven days
- First activity
- Aug 30, 2026
- Last activity
- Aug 31, 2026
- Feed role
- C2
- Host form
- 1 IP / 3 hostnames
HawkEye, also known as Predator Pain or PredatorPain, is a long-running commercially sold credential-stealing malware family for Windows that is commonly categorized as a keylogger but has evolved into a broader infostealer and surveillance trojan.
Profile source: Mallory opens in a new tabHawkEye
HawkEye, also known as Predator Pain or PredatorPain, is a long-running commercially sold credential-stealing malware family for Windows that is commonly categorized as a keylogger but has evolved into a broader infostealer and surveillance trojan. Active since at least the early 2010s, and with reporting that traces its sale and use back even earlier, HawkEye has been marketed on hacking forums and dedicated sales sites, including later variants such as HawkEye Reborn v9. Its broad availability, low cost, and builder-driven customization have made it popular with a wide range of financially motivated operators and opportunistic threat actors.
HawkEye’s core functionality centers on credential theft and user surveillance. Across documented variants, it captures keystrokes, steals clipboard contents, gathers system information, and extracts saved credentials from web browsers, email clients, FTP software, messaging applications, and other desktop applications. Some variants also capture screenshots, collect webcam images, and steal additional application data such as form data or cryptocurrency wallet-related information. Multiple analyses note use of embedded password-recovery utilities and modular components to harvest browser and email credentials.
The malware commonly uses multi-stage execution chains and process injection to evade detection and blend into legitimate activity. Observed variants have used process hollowing or injection into legitimate .NET utilities such as RegAsm.exe and vbc.exe, extracted payload components from resources, and employed obfuscation frameworks including ConfuserEx. Anti-analysis and defense-evasion features reported across samples include anti-debugging checks, security-tool interference, self-deletion, and abuse of Image File Execution Options to impair defensive software. Persistence has been established through Windows Run keys and, in some cases, scheduled tasks.
HawkEye has been distributed primarily through phishing and spearphishing campaigns, often using business-themed lures such as invoices, payment notices, shipping documents, quotations, travel confirmations, and other corporate correspondence. Document-based delivery has included malicious Office files exploiting CVE-2017-11882, as well as compressed archives containing executables. It has also been delivered through loaders, crypters, compromised hosting, and trojanized or fake software. COVID-19-themed spam campaigns also used HawkEye as a payload.
Exfiltration methods vary by build and operator configuration. Documented variants have sent stolen data via SMTP email, FTP, SFTP, HTTP POST, and PHP-based web panels, with some campaigns using periodic automated exfiltration. HawkEye has been used globally across many sectors, including industrial, engineering, manufacturing, transportation, education, government, healthcare-adjacent, and professional services environments. It has featured in financially motivated campaigns such as Operation Ghoul and has also appeared in broader commodity-malware ecosystems alongside loaders, crypters, and other stealers. Its longevity and adaptability have kept it relevant as a widely used credential theft platform.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 47169c00735dc8287955be416ea9f3ba9b6d8a8586b25b789370a96531883d8d 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 ebaf496ed059df538de3f962bc11755ddfb3cd77ee6cc3c24b65c38fa3636946 2f6e932dbb8f3c5fb61da71e12ffadb6901ad4af6d9d48212c4dfa3c7b779512 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e d56e5881ddfb6adf33a9554fece06ff43aae92ee269019a1d8dac7ed764d97d7 Reported operators
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
Exploited software
MITRE ATT&CK
Reporting
Researchers reported that the KeyBase credential-stealing trojan continued to spread widely even after its public takedown, with attackers distributing it through phishing emails and Office exploit kits. The malware steals browser and email passwords, logs keystrokes and clipboard data, captures screenshots, and uploads stolen information to a web management panel known as Keypanel. Analysis of exposed infrastructure found 82 active panels across 64 websites, 933 infected Windows systems, and 125,083 screenshots, showing that operators were still actively collecting data from victims. The exposed screenshots and panel data revealed heavy targeting in India, China, South Korea, the United Arab Emirates, Indonesia, Bangladesh, and Djibouti, with manufacturing, transportation, hospitality, education, and business operations among the affected sectors. Researchers linked campaigns to phishing lures such as purchase orders and aviation-themed messages, and found evidence that attackers used embedded Nirsoft tools including MailPassView and WebBrowserPassView, stored in AES-encrypted form and unpacked at runtime, alongside obfuscated strings and compromised email accounts. The stolen material included banking activity, cargo and purchase-order details, hotel guest information, educational records, and other data consistent with credential theft, invoice fraud, and supply-chain compromise.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.