Cybersecurity experts have identified a sophisticated hacking tool called “Eye Pyramid” being actively deployed in malicious campaigns since mid-January 2025.
This tool, originally open-sourced on GitHub in 2022, has only recently gained traction among threat actors, leveraging Python to deploy various malicious payloads directly into memory without leaving traditional forensic traces on compromised systems.
The Eye Pyramid tool functions as a versatile backdoor, allowing attackers to maintain persistence within compromised networks while deploying additional offensive tools.
Its Python-based architecture enables cross-platform compatibility, making it particularly dangerous for organizations with diverse computing environments.
The tool’s memory-only execution mechanism significantly reduces its detectability by conventional security solutions.
Intrinsec researchers identified a concerning pattern of IP addresses associated with Eye Pyramid command and control servers, many of which are hosted on notorious bulletproof hosting providers including Limenet, Aeza, and Railnet.
These providers are known for their lax policies regarding illicit activities, providing threat actors with resilient infrastructure resistant to takedown efforts.
Further investigation revealed Eye Pyramid’s deployment in conjunction with established malware families, including Cobalt Strike, Sliver, and Rhadamanthys.
Most alarmingly, the tool has been connected to several ransomware operations including Rhysida, Vice Society, and BlackCat, suggesting it has become a preferred component in sophisticated attack chains.
A breakthrough in understanding Eye Pyramid’s operational structure came when Intrinsec’s team discovered a specific JSON file serving as the default error response for Eye Pyramid servers.
This discovery provided crucial linkages between previously disconnected ransomware campaigns.
Analysis of server configurations revealed consistent patterns across multiple threat actors, suggesting either shared tooling or potential collaboration among different ransomware groups.
The infrastructure clustering analysis points to Eye Pyramid becoming an increasingly standardized component in the cybercriminal ecosystem, with its Python-based flexibility allowing for rapid adaptation to evade detection mechanisms.
Are you from the SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…