NEW: Group Profiler — instant APT intel lookup. Try it →

Evilnum

Overview

Evilnum is a financially motivated threat group that has been active since at least 2018.

Naming & attribution

Evilnum is tracked under 1 names across the industry. It uses 11 documented ATT&CK techniques — more than 32% of the 174 groups tracked here. Activity attributed since at least 2018.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
EvilnumPorolli, M

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TA577 — 3 shared techniques (21% overlap)
  • Elderwood China — 3 shared techniques (18% overlap)
  • Molerats — 4 shared techniques (17% overlap)
  • WIRTE — 5 shared techniques (16% overlap)
  • Cobalt Group — 6 shared techniques (15% overlap)
  • LuminousMoth China — 5 shared techniques (15% overlap)

Malware families with current indicators

One family attributed to Evilnum, carrying 36 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Evilnum 36 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

TTPs — 11 techniques across 6 tactics

Initial Access

Execution

Privilege Escalation

Stealth

Command and Control

Tools & malware (3)

More_eggs · EVILNUM · LaZagne

Reporting (1)