Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Evilbyte

Also known as: APT28, Fancy Bear, Paper Werewolf, Sofacy, Pawn Storm, Sednit, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, TA505, SectorJ04

Description

{"paragraph":"Evilbyte is a highly adaptive adversary known by numerous aliases\u2014ranging from APT28 and Fancy Bear to Sednit, Parisite, and Unicorn\u2014which underscores the difficulty in attribution. The actor\u2019s modus operandi blends opportunistic financial motives with politically charged sabotage, evidenced by attacks on government websites, defense contractors, and critical utilities. Their reach extends across continents, targeting sectors as varied as finance, energy, telecommunications, healthcare, manufacturing, and media.","analysis":null,"notes":null}, {"paragraph":"Evilbyte\u2019s toolchain centers on a sophisticated blend of phishing and exploitation. Spear\u2011phishing attachments frequently contain HTA dropper payloads or Office exploits, while domain spoofing and obfuscated file extensions such as \".pdf.lnk\" obscure delivery channels. The actor exploits zero\u2011day web application vulnerabilities (e.g., MDaemon CVE-2024-11182, Ivanti EPMM CVEs 2025-44277\/88, Biotime CVEs 2023\u201138950\/52) and leverages living\u2011off\u2011the\u2011land techniques\u2014PowerShell scripts, WMI, and scheduled tasks\u2014to maintain persistence.","analysis":null,"notes":null}, {"paragraph":"Once inside, Evilbyte deploys a multi\u2011layered command\u2011and\u2011control architecture combining native tools like Cobalt Strike Beacon with custom backdoors (KrustyLoader, Sliver, HanifNet, HXLibrary, NeoExpressRAT). Credential harvesting spans browsers and Telegram data, while exfiltration occurs through embedded HTTP reverse tunnels. The actor often escalates operations by encrypting or deleting backups with SDelete and deploying Babuk ransomware to extract ransom payments.","analysis":null,"notes":null}, {"paragraph":"Campaigns demonstrate a rapid operational tempo; the group routinely pivots between targeting financial services, defense networks, and critical utilities in 2024. Notable incidents include a breach of the Saudi banking system MyFatoorah, an attack on Argentina\u2019s Radio 10 Rosario, and data leaks from Israeli government websites. These operations reveal a dual focus on both monetization through extortion and geopolitical disruption.","analysis":null,"notes":null}

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Energy
Telecommunications
Transportation
Manufacturing
Construction
Healthcare
Education
Utilities
Critical infrastructure
Media
Retail
Aerospace
Nuclear
Non profit
Aviation
Oil gas

Targeted Countries / Regions

RU
TW
CA
AU
KR
US
TR
UA
IL
AE
CN
JP
VN
IN
BR
SA
GB

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 1 day ago

Executive Summary

Evilbyte is an advanced threat actor frequently linked to APT28/Sofacy, operating primarily for financial gain while targeting critical infrastructure and corporate sectors worldwide. Their campaigns combine spear‑phishing with malicious attachments, zero‑day web application vulnerabilities, and sophisticated persistence mechanisms such as scheduled tasks and web shells, often culminating in ransomware deployments (Babuk) and backup destruction with SDelete. Recent operations against energy, defense, fintech, and media organizations demonstrate a blend of sabotage and extortion.

Goals & Targeting

Evilbyte’s strategic objectives marry monetary gain with political influence. By infiltrating high‑value targets in defense, energy, finance, and media, the actor seeks to compel ransom payments while simultaneously destabilizing operations or creating public fear. Political subject line spear‑phishing campaigns suggest an intent to manipulate perceptions as well as generate revenue.

Enhanced Description

Key Capabilities

  • Keystroke logging
  • Zero‑day vulnerability exploitation
  • Spear‑phishing with malicious attachments (HTA dropper, Office exploits)
  • Domain spoofing and site impersonation
  • Obfuscated file extensions (.pdf.lnk)
  • Cobalt Strike Beacon command & control
  • PowerShell living‑off‑the‑land persistence
  • WMI living‑off‑the‑land persistence
  • Scheduled task persistence
  • Remote connections via RDP/SSH/VPN
  • Credential theft from browsers and Telegram data
  • Backup destruction with SDelete
  • Ransomware deployment (Babuk, others)
  • Cloud abuse activity
  • Phishing‑based credential harvesting
  • Direct credential theft
  • Webmail exploitation using XSS
  • Microsoft Teams conversation capture via web client
  • Political subject line spear‑phishing campaigns
  • Zero‑day web application vulnerability exploitation (MDaemon CVE-2024-11182, Office CVE-2012-0158, Ivanti EPMM CVEs 2025-44277/88, Biotime CVEs 2023-38950-52)
  • WebDAV remote code execution via working directory change (CVE-2025-33053)
  • Reflective Java payloads for command execution
  • Use of web shells on publicly accessible servers
  • Custom backdoor deployments (KrustyLoader, Sliver, HanifNet, HXLibrary, NeoExpressRAT, MeshCentral Agent, SystemBC, Auto‑Color Linux backdoor)
  • FRP (Fast Reverse Proxy) for internal reconnaissance and C&C
  • Hardcoded MySQL credentials for data extraction (LDAP details, Office 365 tokens)
  • Custom implant development: Apollo implant evolving into Horus Agent
  • Social engineering via click‑fix technique to induce copy‑paste command execution

MITRE ATT&CK Tactics

Execution
Initial Access
Persistence
Privilege Escalation
Defense Evasion
Command & Control
Credential Access
Exfiltration
Discovery

ATT&CK Techniques

T1027
T1053
T1055
T1057
T1059
T1059.003
T1060
T1078
T1083
T1105
T1185
T1190
T1204
T1204.002
T1555.003
T1490
T1486
T1485
T1489
T1134.002
T1566.001
T1609

Software / Tooling

Unicorn Stealer
Cobalt Strike Beacon
DarkGate
BrockenDoor
Remcos
Babuk Ransomware
SDelete
SpyPress.HORDE
SpyPress.MDAEMON
SpyPress.ROUNDCUBE
SpyPress.ZIMBRA
KrustyLoader
Sliver
Havoc
HanifNet
HXLibrary
NeoExpressRAT
MeshCentral Agent
SystemBC
Auto‑Color Linux backdoor
FRP
Apollo implant
Horus Agent
WastedLocker
HermeticWiper
EVILNUM

Campaigns & Victims

Evilbyte’s operations exhibit a consistent pattern of rapid exploitation and monetization. The actor routinely leverages zero‑day vulnerabilities in popular webmail & application stacks (MDaemon CVEs, Ivanti EPMM RCEs) to launch initial access, followed by spear‑phishing campaigns that use political rhetoric or urgent messaging. Once compromised, the attacker deploys a mix of commercial backdoors and custom implants for lateral movement, with Cobalt Strike Beacon or custom Trojans serving as command and control nodes. They prefer persistent persistence via scheduled tasks, PowerShell scripts, and web shells placed on publicly accessible servers. Backup deletion using SDelete and deployment of Babuk ransomware are common sabotage measures aimed at extracting financial gains. Recent campaigns have targeted defense contractors, energy facilities, financial services, media outlets, and government agencies across North America, Europe, Asia-Pacific, and the Middle East.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Sofacy
  2. www.darktrace.com — Cited by web research for: TA505
  3. www.trendmicro.com — Cited by web research for: T1566
  4. areteir.com — Cited by web research for: Leverage
  5. www.uvcyber.com — Cited by web research for: Dairy

Intel Summary

23

Techniques

63

Tools

0

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

Financial Targeting
Government Targeting
Hacktivism
Retaliatory Attacks
Financial Sector
Government
International Relations

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.