Threat Actors Embrace ‘Eye Pyramid’ in Stealth Malware Campaigns
Security researchers have uncovered a surge in the use of a modular hacking utility known as Eye Pyramid, now a central component in several high-profile cyberattacks traced back to early 2025.
Though the tool was quietly released on GitHub in 2022, it only recently gained prominence among threat actors. Its renewed popularity stems from its ability to inject malicious code directly into system memory using Python—effectively sidestepping traditional detection tools and leaving minimal forensic evidence behind.
Eye Pyramid acts as a flexible backdoor, designed to provide persistent access to infiltrated environments. Its architecture, built on Python, ensures broad platform compatibility—making it an ideal choice for targeting organizations with a heterogeneous mix of devices and operating systems.
One of the tool’s most dangerous features is its in-memory payload execution, a tactic that allows it to operate covertly, beyond the reach of many signature-based defenses.
Investigators at Intrinsec identified clusters of command-and-control infrastructure tied to Eye Pyramid. Many servers were traced to controversial providers like Limenet, Aeza, and Railnet—known for hosting malicious content with minimal oversight. These bulletproof hosts offer threat groups long-term stability and resistance to takedown actions.
Deeper analysis revealed that Eye Pyramid is not used in isolation. It’s often deployed in tandem with other offensive tools such as Cobalt Strike, Sliver, and Rhadamanthys. Alarmingly, it has also been observed in ransomware attacks linked to Vice Society, Rhysida, and BlackCat—hinting at its rising status in coordinated, multi-stage operations.
A pivotal moment in mapping Eye Pyramid’s ecosystem came when analysts uncovered a JSON file consistently returned as an error response by its servers. This artifact became a cornerstone in connecting seemingly unrelated threat campaigns.
Further examination of backend infrastructure revealed overlapping traits among different groups using Eye Pyramid, suggesting a growing level of tool-sharing or strategic cooperation within the cybercriminal underground.
Overall, evidence points to Eye Pyramid becoming a standardized attack component across multiple threat operations, its Python foundation enabling threat actors to continuously morph tactics and stay ahead of detection efforts.




