TA4563 is a financially focused cyber threat actor tracked for campaigns against European financial and investment organizations, including more recent targeting of decentralized finance entities. The actor is associated with use of the EvilNum malware family, a modular backdoor used for reconnaissance, data theft, and delivery of additional payloads. Reported activity overlaps with operations publicly associated with DeathStalker and EvilNum. TA4563 commonly relies on socially engineered, finance-themed lures and staged delivery chains. Observed infection vectors have included Microsoft Word documents using remote templates, ISO container files, and Windows shortcut loaders distributed through cloud-hosted links. The actor’s execution chains have used script interpreters and PowerShell to retrieve and launch subsequent stages, including dynamically loaded C# components and shellcode-based payload decryption. EvilNum activity attributed to this cluster has included screenshot capture, host reconnaissance, and modular payload loading. The actor demonstrates notable defense-evasion tradecraft. Campaigns have used tightly controlled payload delivery, limiting retrieval opportunities, and have adapted execution paths based on the presence of specific antivirus products. TA4563 has also attempted to blend into victim environments by invoking executables likely to already exist on compromised hosts. Tooling associated with this cluster appears to be under active development, with changes observed across campaigns in loader format and execution flow. TA4563 is best understood as a threat cluster linked to EvilNum operations and overlapping with reporting on DeathStalker. Its activity is characterized by targeted intrusion attempts against financial-sector organizations, modular malware deployment, and post-compromise collection behavior consistent with financially motivated espionage and theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
29 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.