11 Dec HawkEye Keylogger Acts as First-Stage Loader for Cryptocurrency Miner
[ad_1]
Researchers observed the HawkEye keylogger acting as the first-stage downloader for a cryptocurrency miner in a new phishing campaign.
As Cofense noted, the phishing campaign began by sending out generic attack emails leveraging fake job applications as a theme. Each of the emails arrived with what appeared at first glance to be a .zip archive containing a job applicant’s resume. When opened, the .zip archive delivered a sample of the HawkEye keylogger.
HawkEye is a piece of malware that’s capable of monitoring systems collecting sensitive information from infected machines and exfiltrating data to a command-and-control (C&C) server under the attacker’s control. These capabilities weren’t active in this campaign, however. Instead, malicious actors used HawkEye’s file installation feature to load a sample of CGMiner. This open-source cryptocurrency miner gave the attackers the ability to mine for different types of virtual currency across all operating systems.
[ad_2]
Source link