Skip to content

Malware

Waterbear

aka DbgPrint · EYEWELL

Waterbear, also known as DbgPrint in its earlier export function, has been active since 2009.

Waterbear, also known as DbgPrint, EYEWELL, is a Windows malware family operated by BlackTech.

Background

Waterbear, named DbgPrint after one of its earlier export functions, has been in operation since 2009. The malware is thought to be the work of the BlackTech APT group and incorporates advanced anti-analysis features along with a forward-looking design. Among these are a refined shellcode stager, on-the-fly plugin loading, and a general tendency to remain evasive if the C2 server does not return a valid session key.


Source: Malpedia (Fraunhofer FKIE).