← threatfilter.dev / all groups / Evilnum
Evilnum
Overview
Evilnum is a financially motivated threat group that has been active since at least 2018.
TTPs — 11 techniques across 6 tactics
Initial Access
-
T1566.002Spearphishing Link
Execution
-
T1059.007JavaScript -
T1204.001Malicious Link
Privilege Escalation
-
T1548.002Bypass User Account Control
Stealth
-
T1070.004File Deletion -
T1497.001System Checks -
T1574.001DLL
Credential Access
Command and Control
-
T1105Ingress Tool Transfer -
T1219.002Remote Desktop Software
Tools & malware (3)
More_eggs · EVILNUM · LaZagne
Reporting (1)
- More evil: A deep look at Evilnum and its toolset — Porolli, M