Skip to content

HawkEye

HawkEye, also known as Predator Pain or PredatorPain, is a long-running commercially sold credential-stealing malware family for Windows that is commonly categorized as a keylogger but has evolved into a broader infostealer and surveillance trojan.

Profile source: Mallory opens in a new tab

HawkEye

Family profile

HawkEye, also known as Predator Pain or PredatorPain, is a long-running commercially sold credential-stealing malware family for Windows that is commonly categorized as a keylogger but has evolved into a broader infostealer and surveillance trojan. Active since at least the early 2010s, and with reporting that traces its sale and use back even earlier, HawkEye has been marketed on hacking forums and dedicated sales sites, including later variants such as HawkEye Reborn v9. Its broad availability, low cost, and builder-driven customization have made it popular with a wide range of financially motivated operators and opportunistic threat actors.

HawkEye’s core functionality centers on credential theft and user surveillance. Across documented variants, it captures keystrokes, steals clipboard contents, gathers system information, and extracts saved credentials from web browsers, email clients, FTP software, messaging applications, and other desktop applications. Some variants also capture screenshots, collect webcam images, and steal additional application data such as form data or cryptocurrency wallet-related information. Multiple analyses note use of embedded password-recovery utilities and modular components to harvest browser and email credentials.

The malware commonly uses multi-stage execution chains and process injection to evade detection and blend into legitimate activity. Observed variants have used process hollowing or injection into legitimate .NET utilities such as RegAsm.exe and vbc.exe, extracted payload components from resources, and employed obfuscation frameworks including ConfuserEx. Anti-analysis and defense-evasion features reported across samples include anti-debugging checks, security-tool interference, self-deletion, and abuse of Image File Execution Options to impair defensive software. Persistence has been established through Windows Run keys and, in some cases, scheduled tasks.

HawkEye has been distributed primarily through phishing and spearphishing campaigns, often using business-themed lures such as invoices, payment notices, shipping documents, quotations, travel confirmations, and other corporate correspondence. Document-based delivery has included malicious Office files exploiting CVE-2017-11882, as well as compressed archives containing executables. It has also been delivered through loaders, crypters, compromised hosting, and trojanized or fake software. COVID-19-themed spam campaigns also used HawkEye as a payload.

Exfiltration methods vary by build and operator configuration. Documented variants have sent stolen data via SMTP email, FTP, SFTP, HTTP POST, and PHP-based web panels, with some campaigns using periodic automated exfiltration. HawkEye has been used globally across many sectors, including industrial, engineering, manufacturing, transportation, education, government, healthcare-adjacent, and professional services environments. It has featured in financially motivated campaigns such as Operation Ghoul and has also appeared in broader commodity-malware ecosystems alongside loaders, crypters, and other stealers. Its longevity and adaptability have kept it relevant as a widely used credential theft platform.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 30, 2026
Last activity
Aug 31, 2026
Feed role
C2
Host form
1 IP / 3 hostnames

Leading locations

  • US2
  • ID1

Leading providers

  • 1337 Services GmbH1
  • Google LLC1
  • Wave Broadband1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

5 named in public reporting
GOLD GALLEON

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

GOLD SKYLINE

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

Mikroceen

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

Get Rich or Die

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

Uche y Okiki

HawkEye, also known as PredatorPain (Predator Pain), is a malware categorized as a keylogger, but over the years, it has adopted new functionalities that align it with the capabilities of other tools like stealers.

Exploited software

Vulnerabilities linked to HawkEye

1 CVEs

MITRE ATT&CK

HawkEye in ATT&CK

50 distinct techniques

Techniques

50 techniques
T1555 Credentials from Password Stores T1056 Input Capture T1566 Phishing T1055 Process Injection T1115 Clipboard Data T1071.001 Web Protocols T1048 Exfiltration Over Alternative Protocol T1125 Video Capture T1113 Screen Capture T1059.010 AutoHotKey & AutoIT T1027.013 Encrypted/Encoded File T1056.001 Keylogging T1497 Virtualization/Sandbox Evasion T1546.012 Image File Execution Options Injection T1055.012 Process Hollowing T1547.001 Registry Run Keys / Startup Folder T1555.003 Credentials from Web Browsers T1082 System Information Discovery T1091 Replication Through Removable Media T1105 Ingress Tool Transfer T1622 Debugger Evasion T1027 Obfuscated Files or Information T1566.001 Spearphishing Attachment T1036 Masquerading T1041 Exfiltration Over C2 Channel T1203 Exploitation for Client Execution T1555.004 Windows Credential Manager T1497.001 System Checks T1071.003 Mail Protocols T1560 Archive Collected Data T1114 Email Collection T1566.002 Spearphishing Link T1071 Application Layer Protocol T1012 Query Registry T1074.001 Local Data Staging T1583.008 Malvertising T1033 System Owner/User Discovery T1562 Impair Defenses T1016 System Network Configuration Discovery T1571 Non-Standard Port T1552 Unsecured Credentials T1204 User Execution T1518.001 Security Software Discovery T1564.001 Hidden Files and Directories T1518 Software Discovery T1053 Scheduled Task/Job T1087 Account Discovery T1005 Data from Local System T1112 Modify Registry T1140 Deobfuscate/Decode Files or Information

Reporting

Research mentioning HawkEye

Aug 11
Nakedsecurity Sophos

Sophos News - The Sophos Blog

Researchers reported that the KeyBase credential-stealing trojan continued to spread widely even after its public takedown, with attackers distributing it through phishing emails and Office exploit kits. The malware steals browser and email passwords, logs keystrokes and clipboard data, captures screenshots, and uploads stolen information to a web management panel known as Keypanel. Analysis of exposed infrastructure found 82 active panels across 64 websites, 933 infected Windows systems, and 125,083 screenshots, showing that operators were still actively collecting data from victims. The exposed screenshots and panel data revealed heavy targeting in India, China, South Korea, the United Arab Emirates, Indonesia, Bangladesh, and Djibouti, with manufacturing, transportation, hospitality, education, and business operations among the affected sectors. Researchers linked campaigns to phishing lures such as purchase orders and aviation-themed messages, and found evidence that attackers used embedded Nirsoft tools including MailPassView and WebBrowserPassView, stored in AES-encrypted form and unpacked at runtime, alongside obfuscated strings and compromised email accounts. The stolen material included banking activity, cargo and purchase-order details, hotel guest information, educational records, and other data consistent with credential theft, invoice fraud, and supply-chain compromise.

Feb 29
Virusbulletin

Virus Bulletin :: New Keylogger on the Block

Feb 25
Palo Alto Networks Unit 42

KeyBase Threat Grows Despite Public Takedown: A Picture is Worth a Thousand Words

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.