Nighthawk

Malware type
rat
Last IoC activity
2026-07-21 16:30:30
Profile updated
2026-07-07 14:50:43

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

Nighthawk is a command-and-control (C2) framework used primarily for remote access and administration. It is often used in targeted attacks against governmental and high-tech industries.

Detection coverage

  • 6 YARA rules

Detection rules

  • SEKOIA_Rat_Win_Nighthawk (yara-rule)
  • SIGNATURE_BASE_EXT_HKTL_Nighthawk_RAT (yara-rule)
  • SIGNATURE_BASE_HKTL_MAL_Nighthawk_Nov_2022_1 (yara-rule)
  • R3C0NST_Nighthawk_RAT (yara-rule)
  • CAPE_Nighthawk (yara-rule)
  • MALPEDIA_Win_Nighthawk_Auto (yara-rule)

Reports & references

  • michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nighthawk (report)
  • github.com — Nighthawk.Py (report)
  • github.com — Nighthawk Str Decoder.Py (report)
  • web.archive.org — Nighthawk And Coming Pentest Tool Likely Gain Threat Actor Notice (report)
  • web.archive.org — Mdsec Nighthawk Study (report)
  • proofpoint.com — Nighthawk And Coming Pentest Tool Likely Gain Threat Actor Notice (report)

External references