Evilnum
Evilnum is a financially motivated threat actor associated with targeting traders, brokerage customers, and financial trading platforms. The content links Evilnum to the DarkMe malware and states that Group-IB attributed DarkMe to Evilnum. Reporting in the content also states that WaterHydra/DarkCasino splintered from Evilnum in late 2022, and that later WaterHydra activity shared a developer path (C:\Users\Administrator\Desktop\vaeeva\shellrundll.tlb) with a July 2022 Evilnum-linked DLL, indicating lineage between the groups. Observed tradecraft in the content includes spearphishing emails containing links to ZIP archives hosted on Google Drive, as well as lures designed to trick recipients into opening malicious shortcut links that result in .LNK download and execution. Evilnum has used malicious JavaScript files on victim machines, used PowerShell to bypass User Account Control, and used TerraLoader to check hardware and file information for sandbox detection. The actor can collect email credentials, obtain usernames from victim machines, and steal browser cookies and web session information. Evilnum has also used Windows Management Instrumentation (WMI) to enumerate infected machines, deployed additional components or tools as needed, and deleted files used during infection for cleanup. The content states that Evilnum used the TerraTV malware variant to load a malicious DLL from the TeamViewer directory instead of the legitimate Windows DLL in a system folder, and to run a legitimate TeamViewer application to connect to compromised machines. This reflects DLL hijacking / sideloading and abuse of legitimate remote desktop software for access to victim systems. The content also notes that Golden Chickens malware-as-a-service has been used by groups including Evilnum. Known aliases and related names directly mentioned in the content: Evilnum / EVILNUM; predecessor group to WaterHydra / DarkCasino.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the MMC/GrimResource detection analytic.
Referenced as a threat actor associated with the execution flow hijack / mock trusted directory MSC file creation technique.
Historical predecessor group tied by lineage and developer artifacts to later WaterHydra/DarkCasino activity. In this content, Evilnum is primarily discussed as the earlier cluster in a lineage chain leading to current DarkMe-related operations.
Earlier cluster connected in the report through a 2022 DarkMe DLL sharing the same developer workspace artifact later seen in WaterHydra samples. The content frames DarkCasino/WaterHydra as initially part of Evilnum before splitting off.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.