Hawkeye keylogger scammers use hacked email accounts to redirect data stolen from infected systems to the attacker's email address.
Security researchers from Trustwave have discovered a spam email campaign that delivers malicious RTF documents disguised as Word files.
The files use the CVE-2010-3333 Office exploit, sometimes also CVE-2012-0158, to infect recipients with the Hawkeye keylogger, a malicious application that is openly sold on the Internet.
Hawkeye is a dangerous threat, which comes with many features that allow crooks to collect emails, browser details ,as well as FTP settings and passwords.
This keylogger enables people to purchase a copy, infect users, collect their data, and then receive it in the form of an email or via FTP data transfer or by uploading it to a PHP website.
Trustwave researchers said that after reverse-engineering a copy of the Hawkeye keylogger, they discovered in one of its configuration files the email address and password for the account to which the keylogger was sending all the stolen data.
Using these credentials, the security researchers logged into the email account, and to their surprise, this wasn't just a dummy account, but belonged to a real person.
"Perhaps the attacker knew that the Hawkeye keylogger could be easily compromised and to protect his own email credentials, he hijacked a compromised email account as the original recipient that eventually forwarded the emails with the attacker's email address," says Trustwave.
The hijacked account included a rule that redirected all messages originating from a specific victim's email address to the inbox .
By not leaving his own password in the keylogger settings, the author avoided the risk of his actions being revealed by security researchers.
It's strange that he used a hijacked email account instead of a dummy inbox, which would have further reduced the chance of being exposed.


