Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 2, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
HawkEye, also known as PredatorPain, is a long-running Windows credential-stealing malware family that originated as a commercial keylogger and evolved into a broader infostealer and downloader used by many unrelated threat actors.
Profile source: Mallory opens in a new tabHawkEye
HawkEye, also known as PredatorPain, is a long-running Windows credential-stealing malware family that originated as a commercial keylogger and evolved into a broader infostealer and downloader used by many unrelated threat actors. It has been sold since at least the late 2000s on criminal forums and dedicated sales sites, with cracked builds later expanding its adoption. HawkEye has been used in phishing, business email compromise, spam, and opportunistic credential-theft operations across multiple sectors worldwide, and it has also appeared in COVID-19-themed lures.
HawkEye is commonly delivered through spearphishing attachments, including malicious documents and compressed archives, as well as through trojanized software and other malware loaders. Many samples are implemented in .NET and use obfuscation and embedded resources to conceal additional components. Typical execution chains involve extracting an injector and payload from resources, copying itself into user-accessible directories, establishing persistence through Run keys and in some cases scheduled tasks, and deleting intermediate artifacts to reduce forensic visibility.
Functionally, HawkEye combines keylogging with broad credential theft. It can steal credentials and other sensitive data from web browsers, email clients, FTP applications, and additional software, and has been associated with theft of clipboard contents, form data, screenshots, system information, and cryptocurrency wallet data. It has also been observed detecting security tools, staging stolen data locally, and exfiltrating information over common application-layer protocols. Some variants perform process hollowing or related injection activity, including launching the payload inside another process. Builder-configurable modules and long-term development have produced substantial variation between samples while preserving the family’s core information-stealing behavior.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e Reported operators
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.