Cyber Security News

Hackers Using New Eye Pyramid Tool to Leverage Python & Deploy Malware

Cybersecurity experts have identified a sophisticated hacking tool called “Eye Pyramid” being actively deployed in malicious campaigns since mid-January 2025.

This tool, originally open-sourced on GitHub in 2022, has only recently gained traction among threat actors, leveraging Python to deploy various malicious payloads directly into memory without leaving traditional forensic traces on compromised systems.

The Eye Pyramid tool functions as a versatile backdoor, allowing attackers to maintain persistence within compromised networks while deploying additional offensive tools.

Its Python-based architecture enables cross-platform compatibility, making it particularly dangerous for organizations with diverse computing environments.

The tool’s memory-only execution mechanism significantly reduces its detectability by conventional security solutions.

Intrinsec researchers identified a concerning pattern of IP addresses associated with Eye Pyramid command and control servers, many of which are hosted on notorious bulletproof hosting providers including Limenet, Aeza, and Railnet.

These providers are known for their lax policies regarding illicit activities, providing threat actors with resilient infrastructure resistant to takedown efforts.

Further investigation revealed Eye Pyramid’s deployment in conjunction with established malware families, including Cobalt Strike, Sliver, and Rhadamanthys.

Most alarmingly, the tool has been connected to several ransomware operations including Rhysida, Vice Society, and BlackCat, suggesting it has become a preferred component in sophisticated attack chains.

Infrastructure Analysis

A breakthrough in understanding Eye Pyramid’s operational structure came when Intrinsec’s team discovered a specific JSON file serving as the default error response for Eye Pyramid servers.

This discovery provided crucial linkages between previously disconnected ransomware campaigns.

Analysis of server configurations revealed consistent patterns across multiple threat actors, suggesting either shared tooling or potential collaboration among different ransomware groups.

The infrastructure clustering analysis points to Eye Pyramid becoming an increasingly standardized component in the cybercriminal ecosystem, with its Python-based flexibility allowing for rapid adaptation to evade detection mechanisms.

Are you from the SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago