Evilnum is a backdoor and malware family associated with the Evilnum threat actor and attributed in the provided content to DeathStalker. It has been used to target European financial and investment entities, as well as foreign exchange and cryptocurrency trading companies. Reported initial access includes spearphishing emails containing Google Drive-hosted ZIP files and malicious shortcut-link lures that lead victims to execute .LNK files or malicious JavaScript. The content also links Evilnum tradecraft continuity to the later VileRAT toolchain used by DeathStalker.
Capabilities directly described in the content include Registry modification for persistence, antivirus/security product discovery, username collection from victim machines, WMI-based host enumeration, cookie and web session theft, email credential theft, file upload over the C2 channel, execution via regsvr32 and rundll32, artifact cleanup, and timestomping by changing file creation dates. Specific behaviors mentioned include searching for anti-virus products on the system, using Windows Management Instrumentation (WMI) to enumerate infected machines, harvesting cookies and uploading them to C2, collecting email credentials, obtaining the username from the victim machine, uploading files over the C2 channel, running a remote scriptlet that drops a file and executes it via regsvr32.exe, and executing commands and scripts through rundll32. The malware also contains a function named "DeleteLeftovers" to remove attack artifacts.
Additional tradecraft attributed to Evilnum in the content includes PowerShell-based UAC bypass, deletion of files used during infection, deployment of additional components or tools, sandbox detection via a component called TerraLoader, and use of the TerraTV variant to side-load a malicious DLL from the TeamViewer directory and run legitimate TeamViewer for remote access. High-confidence behaviors and identifiers from the content include the malware name/alias Evilnum, the function name "DeleteLeftovers," use of regsvr32.exe and rundll32.exe for execution, WMI for enumeration, and theft of browser cookies/session information and email credentials.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We discovered it in Q2 2020 as part of an update of the Evilnum modus operandi, and attributed it to DeathStalker.
"TA4563 is a threat actor leveraging EvilNum malware to target European financial and investment entities... EvilNum is a backdoor that can be used for data theft or to load additional payloads."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
“executing PowerShell via cmd.exe… downloads two different payloads…”; “PowerShell script loads C# code dynamically…”; “executes another PowerShell command… -windowstyle hidden”
“The initial stage LNK loader is responsible for executing PowerShell via cmd.exe…”
APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. ... RogueRobin uses regsvr32.exe to run a .sct file for execution.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
“decrypt a PNG… restart the infection chain”; “payload contains two encrypted blobs… decrypted to an executable… and …TMP… decrypts … to load … shellcode … final decrypted and decompressed PE file.”
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. ... Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DeathStalker-associated malware/campaign referenced as the earlier modus operandi from which the VileRAT activity evolved.
Malware that can alter file creation dates.
A C#-based backdoor used for reconnaissance and data theft, with an execution chain that adapts based on detected antivirus (Avast/AVG/Windows Defender). Delivered via phishing using Word/ISO/LNK, leveraging LNK loaders, wscript, PowerShell, encrypted blobs, and shellcode to ultimately load a final PE payload; can also act as a loader for follow-on payloads.
Malware family referenced in the context of DeathStalker intrusion history; no additional details provided in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.