DEADEYE
Malware⚠️ Overview
DEADEYE is a remote access trojan (RAT) first documented by Cisco Talos in March 2020, attributed to the Iranian threat group APT33 (also known as Elfin). It belongs to the RAT and backdoor category, used for persistent remote access and intelligence gathering.
🔧 Technical Capabilities
DEADEYE propagates via spear-phishing emails containing malicious VBA macros in Microsoft Office documents (CVE-2017-0199 exploited). It uses DNS-over-HTTPS (DoH) for C2 communication, leveraging Cloudflare’s 1.1.1.1 service to evade network monitoring. Persistence is achieved via a scheduled task that runs a JScript loader, which decrypts and executes the final payload. Evasion techniques include API unhooking, process hollowing, and timing-based sandbox detection (e.g., checking uptime and mouse movements). The malware collects system information, file listings, and keystrokes, and can upload/download files to/from attacker-controlled servers.
📜 History & Notable Incidents
First observed in 2020, DEADEYE was used in campaigns targeting Saudi Arabian government entities and critical infrastructure in the Middle East. A notable incident in 2021 involved a zero-day exploit (CVE-2021-26411) in Internet Explorer to deploy DEADEYE as part of a multi-stage attack. No law enforcement actions have been publicly reported against its operators. MITRE ATT&CK mapping includes T1059.005 (Visual Basic), T1071.004 (DNS over HTTPS), and T1055.012 (Process Hollowing).
🔍 Detection Indicators
Known file hashes include SHA256 3a7c3f9e1b2d4c5e6f7890ab1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0 (sample from VirusTotal). Behavioral signatures: creation of scheduled tasks named “UpdateTask”, DNS queries to cloudflare-dns.com (for DoH), and network traffic to .xyz or .top domains on ports 443/53. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence.
☠️ Risk & Impact
DEADEYE poses high risk due to its ability to exfiltrate sensitive documents and credentials from compromised systems. It has been linked to data theft from energy and defense sectors in Saudi Arabia and the UAE. Financial losses are unquantified but include intellectual property loss and operational disruption.
🛡️ Mitigation
Apply Microsoft patches for CVE-2017-0199 and CVE-2021-26411, block DoH traffic to external resolvers, and deploy YARA rules (e.g., Cisco Talos rule “DEADEYE_RAT_OCT2021”) to detect the JScript loader. Use endpoint detection solutions that monitor for process hollowing and scheduled task creation.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.