Also known as: APT28, Fancy Bear, Paper Werewolf, Sofacy, Pawn Storm, Sednit, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, TA505, SectorJ04
{"paragraph":"Evilbyte is a highly adaptive adversary known by numerous aliases\u2014ranging from APT28 and Fancy Bear to Sednit, Parisite, and Unicorn\u2014which underscores the difficulty in attribution. The actor\u2019s modus operandi blends opportunistic financial motives with politically charged sabotage, evidenced by attacks on government websites, defense contractors, and critical utilities. Their reach extends across continents, targeting sectors as varied as finance, energy, telecommunications, healthcare, manufacturing, and media.","analysis":null,"notes":null}, {"paragraph":"Evilbyte\u2019s toolchain centers on a sophisticated blend of phishing and exploitation. Spear\u2011phishing attachments frequently contain HTA dropper payloads or Office exploits, while domain spoofing and obfuscated file extensions such as \".pdf.lnk\" obscure delivery channels. The actor exploits zero\u2011day web application vulnerabilities (e.g., MDaemon CVE-2024-11182, Ivanti EPMM CVEs 2025-44277\/88, Biotime CVEs 2023\u201138950\/52) and leverages living\u2011off\u2011the\u2011land techniques\u2014PowerShell scripts, WMI, and scheduled tasks\u2014to maintain persistence.","analysis":null,"notes":null}, {"paragraph":"Once inside, Evilbyte deploys a multi\u2011layered command\u2011and\u2011control architecture combining native tools like Cobalt Strike Beacon with custom backdoors (KrustyLoader, Sliver, HanifNet, HXLibrary, NeoExpressRAT). Credential harvesting spans browsers and Telegram data, while exfiltration occurs through embedded HTTP reverse tunnels. The actor often escalates operations by encrypting or deleting backups with SDelete and deploying Babuk ransomware to extract ransom payments.","analysis":null,"notes":null}, {"paragraph":"Campaigns demonstrate a rapid operational tempo; the group routinely pivots between targeting financial services, defense networks, and critical utilities in 2024. Notable incidents include a breach of the Saudi banking system MyFatoorah, an attack on Argentina\u2019s Radio 10 Rosario, and data leaks from Israeli government websites. These operations reveal a dual focus on both monetization through extortion and geopolitical disruption.","analysis":null,"notes":null}
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Evilbyte is an advanced threat actor frequently linked to APT28/Sofacy, operating primarily for financial gain while targeting critical infrastructure and corporate sectors worldwide. Their campaigns combine spear‑phishing with malicious attachments, zero‑day web application vulnerabilities, and sophisticated persistence mechanisms such as scheduled tasks and web shells, often culminating in ransomware deployments (Babuk) and backup destruction with SDelete. Recent operations against energy, defense, fintech, and media organizations demonstrate a blend of sabotage and extortion.
Goals & Targeting
Evilbyte’s strategic objectives marry monetary gain with political influence. By infiltrating high‑value targets in defense, energy, finance, and media, the actor seeks to compel ransom payments while simultaneously destabilizing operations or creating public fear. Political subject line spear‑phishing campaigns suggest an intent to manipulate perceptions as well as generate revenue.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Evilbyte’s operations exhibit a consistent pattern of rapid exploitation and monetization. The actor routinely leverages zero‑day vulnerabilities in popular webmail & application stacks (MDaemon CVEs, Ivanti EPMM RCEs) to launch initial access, followed by spear‑phishing campaigns that use political rhetoric or urgent messaging. Once compromised, the attacker deploys a mix of commercial backdoors and custom implants for lateral movement, with Cobalt Strike Beacon or custom Trojans serving as command and control nodes. They prefer persistent persistence via scheduled tasks, PowerShell scripts, and web shells placed on publicly accessible servers. Backup deletion using SDelete and deployment of Babuk ransomware are common sabotage measures aimed at extracting financial gains. Recent campaigns have targeted defense contractors, energy facilities, financial services, media outlets, and government agencies across North America, Europe, Asia-Pacific, and the Middle East.
No campaigns linked yet.
No observed data linked yet.
23
Techniques
63
Tools
0
Campaigns
40
IOCs
0
Observed Data
9
Tactics