Evilnum is a Windows-focused malware family associated with the DeathStalker threat actor and used in low-volume, highly targeted intrusions, particularly against financial technology organizations involved in forex, cryptocurrency trading, and related compliance functions. It has also been observed against legal and intergovernmental targets in Europe and the Middle East. Evilnum has existed in multiple implementations, including JavaScript and .NET variants, and later activity overlaps with the Python-based PyVil/VileRAT toolchain attributed to the same actor cluster.
Evilnum commonly functions as an initial-stage implant used to profile compromised hosts and support delivery of additional tooling. Documented behaviors include collecting the current username, enumerating host details through WMI, checking for installed antivirus or other security products, harvesting browser cookies, uploading files over its command-and-control channel, and removing attack artifacts through cleanup routines. Some variants also altered file creation timestamps to hinder forensic analysis.
Persistence on Windows has been achieved through Registry Run-key mechanisms, including modification of Windows Registry autorun locations. Execution tradecraft includes abuse of regsvr32 to run remote COM scriptlets that drop and launch follow-on payloads. More recent Evilnum campaigns used spearphishing against selected victims, historically with ZIP archives containing shortcut-based lures and later with malicious Word documents using remote template injection, VBA stomping, and heavily obfuscated JavaScript. In those later chains, JavaScript established persistence via scheduled tasks, dropped a loader and encrypted payload, and launched an in-memory backdoor capable of beaconing, exfiltrating host metadata, capturing machine snapshots on command, and downloading and executing additional content.
Evilnum operations are characterized by careful victim selection, strong obfuscation, and masquerading of artifacts as legitimate software components. Reporting has also noted possible operational and tooling relationships between Evilnum and other DeathStalker-associated malware families, including Janicab, PowerSing, PowerPepper, and Cardinal RAT, though overlaps do not always establish a single common operator with certainty.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Overall, Janicab shows the same functionalities as its counterpart malware families, but instead of downloading several tools later in the intrusion lifecycle, as was the case with EVILNUM and Powersing intrusions...
Since the beginning of 2022, ThreatLabz has been closely monitoring the activities of the Evilnum APT group... In this blog, we present the technical details of all components involved in the end-to-end attack chain.
"TA4563 is a threat actor leveraging EvilNum malware to target European financial and investment entities... EvilNum is a backdoor that can be used for data theft or to load additional payloads."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The delivery methods for each family do not share any similarities... Do not allow inbound e-mails with LNK file as attachments, or, do not allow inbound e-mails with attached ZIP files containing a single LNK file inside them. Do not allow inbound e-mails from external sources where the documents contain macros... Both families have been distributed using malicious documents containing lists of names/numbers of individuals involved in trading forex/crypto currency.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
Cobalt Group has used regsvr32.exe to execute scripts. Saint Bot has used regsvr32 to execute scripts. Xbash can use regsvr32 for executing scripts.
The DLL begins by performing a sleep using the built-in Windows choice utility: cmd.exe /c choice /C Y /N /D Y /T 20... EVILNUM’s supported commands vary from version to version and include but are not limited to: Run an arbitrary command using “cmd /c”
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
“decrypt a PNG… restart the infection chain”; “payload contains two encrypted blobs… decrypted to an executable… and …TMP… decrypts … to load … shellcode … final decrypted and decompressed PE file.”
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
211 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A targeted malware/toolset used in spear-phishing campaigns against primarily UK and European organizations. The chain uses malicious Word documents with template injection, VBA code stomping, heavily obfuscated JavaScript, a scheduled-task-based loader, and a main backdoor that decrypts configuration, beacons to C2, exfiltrates host data and snapshots, and can download and execute additional payloads.
A DeathStalker-associated malware/campaign referenced as the earlier modus operandi from which the VileRAT activity evolved.
Malware that can alter file creation dates.
Backdoor that can obtain the username from the victim machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.