Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Evilnum

Also known as: DeathStalker, TA4563, EvilNum, Jointworm, KNOCKOUT SPIDER

Description

Evilnum is a financially motivated threat group that has been active since at least 2018.(Citation: ESET EvilNum July 2020)

AI Analysis

· 1 week ago

Executive Summary

Evilnum, also known as DeathStalker, TA4563, Jointworm, and Knockout Spider, is a financially motivated threat group active since at least 2018. They are known for their advanced persistent threat (APT) tactics and have targeted sectors including finance and retail for data theft and financial gain.

Goals & Targeting

Evilnum primarily targets sectors with high financial value, such as finance and retail, where sensitive data can be monetized. Their targeting often includes geographies with significant economic activity or industries with weak security postures.

Enhanced Description

Evilnum operates with a primary focus on financial motivations, leveraging sophisticated techniques to compromise organizations. The group is known to deploy multi-stage attacks involving initial access through phishing, followed by the deployment of custom malware such as EVILNUM and More_eggs. Their activities often involve credential harvesting, system persistence, and data exfiltration to achieve their financial objectives. Evilnum has demonstrated a high level of operational continuity since first being observed in 2018.

Key Capabilities

  • Advanced persistent threat (APT) tactics
  • Custom malware development (EVILNUM, More_eggs)
  • Spearphishing campaigns
  • DLL injection techniques
  • Credential harvesting from password stores

MITRE ATT&CK Tactics

Collection
Exfiltration
Defense Evasion
Discovery
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1059.007
T1497.001
T1566.002
T1574.001
T1555
T1070.004
T1204.001
T1539
T1548.002
T1219.002
T1105

Software / Tooling

EVILNUM
More_eggs

Campaigns & Victims

Evilnum has been linked to numerous campaigns targeting financial and retail sectors. Their operations typically involve initial access through phishing, followed by lateral movement and data exfiltration. Campaign patterns include the use of legitimate tools for malicious purposes and long-term persistence within networks.

IOC Patterns

  • Spearphishing links
  • JavaScript injection attacks
  • Malicious macro-laced Office documents
  • DLL injection activities
  • C2 communication over established protocols

Recommended Actions

  • Implement robust email filtering and phishing detection solutions.
  • Monitor for unusual network activity, particularly C2 behavior.
  • Patch systems to prevent known vulnerabilities exploited by Evilnum.
  • Educate employees on recognizing spearphishing attempts.

Suggested Tags

APT
Financially motivated
Finance sector
零售业

Confidence Assessment

Confidence in data about Evilnum is medium to high for some aspects, such as their financial motivation and toolset. However, gaps exist in understanding their exact origins and long-term strategic objectives.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. ESET EvilNum July 2020 — Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

Intel Summary

11

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

6

Tactics

Tags

APT
Financially motivated
Finance sector
零售业

Details

MITRE ID
G0120
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--1f0f9a14-11aa-49aa-9174-bcd0eaa979de
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.