Evilnum is a Windows malware family with JavaScript and .NET implementations, used in targeted intrusions against financial technology organizations, particularly businesses involved in foreign-exchange trading, cryptocurrency trading, and compliance. It is associated with the Evilnum threat group and activity linked to DeathStalker. The malware serves as an initial-stage implant that profiles compromised systems, exfiltrates files, and facilitates the deployment and execution of additional malicious tools.
Evilnum collects victim usernames, enumerates host information through Windows Management Instrumentation, and identifies installed antivirus products. It uploads files through its command-and-control channel and establishes persistence through Windows Registry autostart entries. It can execute remote scriptlets using a legitimate Windows COM registration utility to drop and launch additional payloads. Its defense-evasion and anti-forensic behaviors include changing file creation timestamps and removing attack artifacts.
Delivery commonly involves targeted phishing with customer identity-verification lures, including malicious Windows shortcuts disguised as identity documents. Evilnum-associated campaigns have also used malicious Word documents and remote macro templates to initiate multistage infection chains. Targeting has been concentrated in the United Kingdom and Europe, with related observations involving Israeli financial technology organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Overall, Janicab shows the same functionalities as its counterpart malware families, but instead of downloading several tools later in the intrusion lifecycle, as was the case with EVILNUM and Powersing intrusions...
Since the beginning of 2022, ThreatLabz has been closely monitoring the activities of the Evilnum APT group... In this blog, we present the technical details of all components involved in the end-to-end attack chain.
"TA4563 is a threat actor leveraging EvilNum malware to target European financial and investment entities... EvilNum is a backdoor that can be used for data theft or to load additional payloads."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The delivery methods for each family do not share any similarities... Do not allow inbound e-mails with LNK file as attachments, or, do not allow inbound e-mails with attached ZIP files containing a single LNK file inside them. Do not allow inbound e-mails from external sources where the documents contain macros... Both families have been distributed using malicious documents containing lists of names/numbers of individuals involved in trading forex/crypto currency.
Cobalt Group has used regsvr32.exe to execute scripts. Saint Bot has used regsvr32 to execute scripts. Xbash can use regsvr32 for executing scripts.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
211 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A targeted malware/toolset used in spear-phishing campaigns against primarily UK and European organizations. The chain uses malicious Word documents with template injection, VBA code stomping, heavily obfuscated JavaScript, a scheduled-task-based loader, and a main backdoor that decrypts configuration, beacons to C2, exfiltrates host data and snapshots, and can download and execute additional payloads.
A DeathStalker-associated malware/campaign referenced as the earlier modus operandi from which the VileRAT activity evolved.
Malware that can alter file creation dates.
Backdoor that can obtain the username from the victim machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.