DEADEYE

MITRE ATT&CK: S1052 View on attack.mitre.org

Aliases: DEADEYE.EMBED, DEADEYE.APPEND, DEADEYE

First seen
2021-05-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:26:31

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services education-and-nonprofits

Targeted regions: country_code:us country_code:cn country_code:ru

Context

DEADEYE is a malware launcher that has been used by APT41 since at least May 2021. DEADEYE has variants that can either embed a payload inside a compiled binary (DEADEYE.EMBED) or append it to the end of a file (DEADEYE.APPEND).

Detection coverage

  • 152 Sigma rules

Malware & tools used

  • Execution Guardrails (attack-pattern)
  • Msiexec (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Native API (attack-pattern)
  • Rundll32 (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)

Used by threat actors

  • C0017 (campaign)

Reports & references

  • Mandiant — Apt41 Us State Governments (report)
  • MITRE ATT&CK — S1052 (report)

External references