Skip to main content
Mallory
MalwareUsed by 3 actors

EVILNUM

Evilnum is a backdoor malware family associated with the Evilnum threat actor, including reporting that TA4563 has leveraged it against European financial and investment entities. The malware is used for data theft and to load additional payloads. Reported initial access includes spearphishing emails containing links to Google Drive-hosted ZIP archives and lures that trick victims into opening malicious shortcut links, resulting in download of a .LNK file; malicious JavaScript has also been used on victim machines. Observed capabilities include collecting email credentials, harvesting browser cookies and web session information, uploading stolen data and files over its command-and-control channel, and deploying additional components or tools as needed. On infected hosts, Evilnum has used WMI to enumerate machines and search for installed antivirus products, modified the Windows Registry for persistence, used PowerShell to bypass UAC, executed remote scriptlets that drop files and run them via regsvr32.exe, and executed commands and scripts through rundll32. Defense-evasion and anti-forensics behaviors include changing file creation dates, deleting files used during infection, and a function named DeleteLeftovers to remove attack artifacts. Related tooling and variants mentioned in the content include TerraLoader, used to check hardware and file information for sandbox detection, and the TerraTV variant, which loads a malicious DLL from the TeamViewer directory and runs legitimate TeamViewer software to connect to compromised machines.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Evilnum

Evilnum can collect email credentials from victims.

via mitre attackattack.mitre.org
ta4563

"TA4563 is a threat actor leveraging EvilNum malware to target European financial and investment entities... EvilNum is a backdoor that can be used for data theft or to load additional payloads."

via proofpoint threat insight blogproofpoint.com
Deathstalker

"TA4563 is a threat actor leveraging EvilNum malware to target European financial and investment entities... EvilNum is a backdoor that can be used for data theft or to load additional payloads."

via proofpoint threat insight blogproofpoint.com
MITRE ATT&CK

Techniques & procedures

26 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566.001Spearphishing AttachmentEvidence1

“The identified campaigns delivered an updated version of the EvilNum backdoor using a varied mix of ISO, Microsoft Word and Shortcut (LNK) files…”; “The messages purported to be related to financial trading platform registration…”

T1566.003Spearphishing via ServiceEvidence1

“attempting to deliver multiple OneDrive URLs that contained either an ISO or .LNK attachment.”

Execution

6 techniques
T1047Windows Management InstrumentationEvidence3
TacticExecution

The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'

T1059.001PowerShellEvidence1
TacticExecution

“executing PowerShell via cmd.exe… downloads two different payloads…”; “PowerShell script loads C# code dynamically…”; “executes another PowerShell command… -windowstyle hidden”

T1059.003Windows Command ShellEvidence1
TacticExecution

“The initial stage LNK loader is responsible for executing PowerShell via cmd.exe…”

T1059.005Visual BasicEvidence1
TacticExecution

APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. ... RogueRobin uses regsvr32.exe to run a .sct file for execution.

T1059.007JavaScriptEvidence1
TacticExecution

“leveraging wscript to load the EvilNum payload, and a JavaScript payload that was ultimately installed on the user's host.”

T1204User ExecutionEvidence1
TacticExecution

“used financial lures to get the recipient to launch the EvilNum payload.”

Persistence

2 techniques
T1112Modify RegistryEvidence5

The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.

T1547.001Registry Run Keys / Startup FolderEvidence5

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.

T1547.001Registry Run Keys / Startup FolderEvidence5

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.

Stealth

9 techniques
T1070Indicator RemovalEvidence3
TacticStealth

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.

T1070.004File DeletionEvidence2
TacticStealth

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.

T1070.006TimestompEvidence2
TacticStealth

APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

“decrypt a PNG… restart the infection chain”; “payload contains two encrypted blobs… decrypted to an executable… and …TMP… decrypts … to load … shellcode … final decrypted and decompressed PE file.”

T1218System Binary Proxy ExecutionEvidence1
TacticStealth

“leveraging wscript to load the EvilNum payload…”

T1218.010Regsvr32Evidence2
TacticStealth

AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. ... Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.

T1218.011Rundll32Evidence1
TacticStealth
T1221Template InjectionEvidence1
TacticStealth

“These messages used a remote template document… attempting to communicate with domains to install several LNK loader components…”; “delivered Microsoft Word documents to attempt to download a remote template.”

T1497.001System ChecksEvidence1

“executed depending on what antivirus software – either Avast, AVG, or Windows Defender – is found on the host… execution chain will change to best evade detection…”

T1112Modify RegistryEvidence5

The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.

T1539Steal Web Session CookieEvidence2

"APT42 has used custom malware to steal login and cookie data from common browsers." / "...extracts the web session cookie and sends it to the C2 server." / "...stole Chrome browser cookies by copying the Chrome profile directories of targeted users."

Discovery

3 techniques
T1033System Owner/User DiscoveryEvidence3
TacticDiscovery

The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking admin status, and enumerating user sessions.

T1082System Information DiscoveryEvidence4
TacticDiscovery

The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."

T1497.001System ChecksEvidence1

“executed depending on what antivirus software – either Avast, AVG, or Windows Defender – is found on the host… execution chain will change to best evade detection…”

Collection

1 technique
T1113Screen CaptureEvidence1

“sends screenshots to a command-and-control server (C2).”

T1102.003One-Way CommunicationEvidence1
T1105Ingress Tool TransferEvidence2

“downloads two different payloads from the initial host (e.g. infntio[.]com).”

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence3

ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.

INDICATORS OF COMPROMISE

IOCs tracked for this family

29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
14 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
5 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
10 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching29

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping26

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.