Evil Corp is a Russian cybercriminal group active since at least 2007 and widely known for major banking malware, loader, and ransomware operations. The group is strongly associated with the Zeus and Dridex malware ecosystems and has also been linked to SocGholish, a fake-browser-update loader used to obtain initial access through compromised websites. Reported aliases include EvilCorp, Gold Drake, Indrik Spider, DEV-0243, Manatee Tempest, and UNC2165. The group has historically specialized in financially motivated intrusions, including banking fraud, credential theft, malware distribution, and large-scale money laundering. Over time, its operations expanded from banking trojans into ransomware and post-compromise monetization. Evil Corp has been associated with ransomware operations including WastedLocker, Hades, Macaw Locker, and Phoenix CryptoLocker. It has also been tied to initial-access activity that enabled downstream deployment of additional malware and ransomware. Operationally, Evil Corp has used malware loaders and compromised web infrastructure to gain footholds, notably through SocGholish campaigns that rely on hacked websites and fake browser update lures. The group has been linked to malware and tooling that support persistence, credential access, proxying, tunneling, and post-exploitation. Reporting also links Evil Corp to VIPERTUNNEL, a backdoor that establishes SOCKS5 proxy tunnels and uses staged in-memory execution and encrypted command-and-control. Broader reporting connects the group to credential theft, keylogging, exfiltration, defense evasion, and initial access brokering behavior. Evil Corp is regarded as one of Russia’s most prominent cybercrime organizations and has repeatedly been associated with ransomware-enabling infrastructure, bulletproof hosting usage, and laundering of criminal proceeds. Its activity spans financially driven intrusion chains from initial compromise through credential theft, access resale or reuse, and ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The vulnerability, identified as CVE-2024-37085, involves a domain group whose members are granted full administrative access to the ESXi hypervisor by default without proper validation... VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default.
GTIG identified UNC2165... leveraging CVE-2025-8088 to distribute malware in mid-July 2025.
Beukema added that "there is a reason attackers still like LNK files - users quickly click through these sorts of warnings. Otherwise, CVE-2025-9491 wouldn't have been as 'successful' as it was either." CVE-2025-9491 ... can be exploited to hide command-line arguments by using excessive whitespace padding. ... widely exploited by at least 11 state-sponsored groups and cybercrime gangs ... Mustang Panda ... exploiting this Windows vulnerability in zero-day attacks ... to deploy the PlugX remote access trojan (RAT).
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a background association tied to an infrastructure operator, not as a focus of the article.
Cybercriminal group cited as using the sanctioned bulletproof hosting service Media Land LLC.
Named as one of the ransomware operations facilitated by Media Land LLC.
Referenced as the Russian cybercrime group tied to the SocGholish malware installer used via hacked websites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.