HAWKBALL

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[HAWKBALL](https://attack.mitre.org/software/S0391) is a backdoor that was observed in targeting of the government sector in Central Asia.(Citation: FireEye HAWKBALL Jun 2019)

Associated Techniques (11)
ID ATT&CK Tactics
T1027.013 Encrypted/Encoded File -
T1033 System Owner/User Discovery -
T1041 Exfiltration Over C2 Channel -
T1059.003 Windows Command Shell -
T1070.004 File Deletion -
T1071.001 Web Protocols -
T1082 System Information Discovery -
T1106 Native API -
T1203 Exploitation for Client Execution -
T1559.002 Dynamic Data Exchange -
T1560.003 Archive via Custom Method -
Metadata
ID: 60
Created: 13/01/2026 17:48
Updated: 22/04/2026 16:00