Evilnum
Overview
Evilnum is a financially motivated threat group that has been active since at least 2018.
Naming & attribution
Evilnum is tracked under 1 names across the industry. It uses 11 documented ATT&CK techniques — more than 32% of the 174 groups tracked here. Activity attributed since at least 2018.
| Name | First reported by |
|---|---|
| Evilnum | Porolli, M |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- TA577 — 3 shared techniques (21% overlap)
- Elderwood China — 3 shared techniques (18% overlap)
- Molerats — 4 shared techniques (17% overlap)
- WIRTE — 5 shared techniques (16% overlap)
- Cobalt Group — 6 shared techniques (15% overlap)
- LuminousMoth China — 5 shared techniques (15% overlap)
Malware families with current indicators
One family attributed to Evilnum, carrying 36 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Evilnum 36 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
TTPs — 11 techniques across 6 tactics
Initial Access
-
T1566.002Spearphishing Link
Execution
-
T1059.007JavaScript -
T1204.001Malicious Link
Privilege Escalation
-
T1548.002Bypass User Account Control
Stealth
-
T1070.004File Deletion -
T1497.001System Checks -
T1574.001DLL
Credential Access
Command and Control
-
T1105Ingress Tool Transfer -
T1219.002Remote Desktop Software
Tools & malware (3)
More_eggs · EVILNUM · LaZagne
Reporting (1)
- More evil: A deep look at Evilnum and its toolset — Porolli, M