Skip to content

HawkEye

HawkEye, also known as PredatorPain, is a long-running Windows credential-stealing malware family that originated as a commercial keylogger and evolved into a broader infostealer and downloader used by many unrelated threat actors.

Profile source: Mallory opens in a new tab

HawkEye

Family profile

HawkEye, also known as PredatorPain, is a long-running Windows credential-stealing malware family that originated as a commercial keylogger and evolved into a broader infostealer and downloader used by many unrelated threat actors. It has been sold since at least the late 2000s on criminal forums and dedicated sales sites, with cracked builds later expanding its adoption. HawkEye has been used in phishing, business email compromise, spam, and opportunistic credential-theft operations across multiple sectors worldwide, and it has also appeared in COVID-19-themed lures.

HawkEye is commonly delivered through spearphishing attachments, including malicious documents and compressed archives, as well as through trojanized software and other malware loaders. Many samples are implemented in .NET and use obfuscation and embedded resources to conceal additional components. Typical execution chains involve extracting an injector and payload from resources, copying itself into user-accessible directories, establishing persistence through Run keys and in some cases scheduled tasks, and deleting intermediate artifacts to reduce forensic visibility.

Functionally, HawkEye combines keylogging with broad credential theft. It can steal credentials and other sensitive data from web browsers, email clients, FTP applications, and additional software, and has been associated with theft of clipboard contents, form data, screenshots, system information, and cryptocurrency wallet data. It has also been observed detecting security tools, staging stolen data locally, and exfiltrating information over common application-layer protocols. Some variants perform process hollowing or related injection activity, including launching the payload inside another process. Builder-configurable modules and long-term development have produced substantial variation between samples while preserving the family’s core information-stealing behavior.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 2, 2026
Last activity
Aug 2, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • US1

Leading providers

  • Google LLC1

Infrastructure traits

  • Hosting 1
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

5 named in public reporting
GOLD GALLEON

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

GOLD SKYLINE

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

Mikroceen

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

Get Rich or Die

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

Uche y Okiki

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

MITRE ATT&CK

HawkEye in ATT&CK

36 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.