EvilPost is a targeted intrusion cluster observed using spear-phishing documents that exploit Microsoft Office vulnerability CVE-2015-2545 for initial access. Activity publicly documented in late 2015 targeted the Japanese defense sector. The infection chain used a malicious DOCX containing an embedded EPS object to execute shellcode, followed by deployment of additional malware components and exploitation of CVE-2015-1701 to elevate privileges to Local System. EvilPost has been associated with staged payload delivery involving architecture-specific DLL components and command-and-control hosted on compromised infrastructure. The actor’s observed tradecraft includes phishing-based initial compromise, exploit-driven execution, privilege escalation, and post-compromise malware retrieval. Available information is limited, and no high-confidence public attribution to a specific state or country is established from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
...dropped and loaded a 32-bit or 64-bit DLL file depending on the system architecture. This, in turn exploited another vulnerability to elevate privileges to Local System (CVE-2015-1701)...
CVE-2015-2545 is a vulnerability discovered in 2015 and corrected with Microsoft’s update MS15-099... enables an attacker to execute arbitrary code using a specially crafted EPS image file... exploited in the wild in August 2015... used in targeted attack by the Platinum group.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.