HomeSecurityHackers use Eye Pyramid Tool to develop malware

Hackers use Eye Pyramid Tool to develop malware

Cybersecurity experts have identified a sophisticated hacking tool called “Eye Pyramid,” which has been actively used in malicious campaigns since mid-January 2025.

See also: Tsunami malware features Miners and Credential Stealers

Eye Pyramid

This tool, which was originally made available as open source on GitHub in 2022, has only recently gained popularity among cybercriminals, leveraging the Python to directly load malicious payloads into memory, without leaving traditional digital traces on compromised systems.

Eye Pyramid acts as a flexible “backdoor,” allowing attackers to maintain access to compromised networks and deploy additional attack tools. Its Python-based architecture offers compatibility with multiple operating systems, making it particularly dangerous for organizations with heterogeneous computing environments.

The tool's memory-only execution mechanism significantly reduces its detectability by traditional security solutions.

See also: New DslogdRAT malware is distributed via vulnerability in Ivanti Connect Secure

Intrinsec researchers have identified a disturbing pattern of IP addresses connected to Eye Pyramid command and control (C2) servers, many of which are hosted on notorious “bulletproof hosting” service providers such as Limenet, Aeza , and Railnet.

hackers vulnerability

These providers are known for their flexible stance towards illegal activities, offering cybercriminals infrastructures with high resilience to attempts to terminate their operations.

Further research revealed that Eye Pyramid is used in conjunction with established malware families, such as Cobalt Strike, Sliver , and Rhadamanthys.

Even more worrying is the fact that the tool has been associated with several ransomware attacks, including Rhysida, Vice Society , and BlackCat, suggesting that it is now a key element in complex cyberattack chains.

See also: New XorDDoS malware allows creation of DDoS botnets

Related to the above is the increasing use of fileless malware , a technique that, like Eye Pyramid, exploits the execution of malicious code exclusively in the system’s memory. This type of threat is particularly dangerous, as it leaves no traces on the disk, which makes it difficult to detect by traditional antivirus and EDR (Endpoint Detection and Response) systems. Another related development is the tendency of attackers to use “living-off-the-land” techniques, i.e. to exploit legitimate operating system tools (e.g. PowerShell, WMI, or Python if installed) for the attack, further reducing their footprint.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS