Evil Corp, also tracked here as Water Asena, is a financially motivated cybercriminal threat actor associated with large-scale malware distribution and intrusion activity. In the referenced activity, the group was linked to Raspberry Robin campaigns that exploited the Windows shortcut user-interface misrepresentation flaw ZDI-CAN-25373 to conceal malicious command-line execution within crafted .lnk files. This tradecraft relies on deceptive shortcut presentation and hidden arguments to reduce user scrutiny and facilitate payload delivery. The actor’s observed behavior in this context supports capabilities in initial access, defense evasion, and post-exploitation through the use of malicious shortcut files and malware delivery infrastructure. Evil Corp is widely known in the industry under the Evil Corp name, while Water Asena is an alternate tracking label. The supplied facts directly support its use of the .lnk-based exploitation technique in Raspberry Robin-related operations, but do not provide high-confidence detail here on specific victim countries, sectors, or extortion tactics for this actor in this activity set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor observed exploiting ZDI-CAN-25373 as part of Raspberry Robin campaigns.
Water Asena (Evil Corp) is a cybercriminal group that exploited ZDI-CAN-25373 in Raspberry Robin campaigns, likely for financial gain and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.