EvilGrab is a Windows remote access trojan associated with China-linked espionage activity, particularly APT10. It has been used as tactical malware for initial compromise and early foothold establishment, including in spearphishing operations delivering malicious Microsoft Office documents and in at least one observed case exploiting CVE-2012-0158. EvilGrab supports surveillance and collection functions including screenshot capture, keystroke logging, audio capture, and video capture from infected systems. It is also capable of maintaining persistence through Windows Registry Run key modification. In reported APT10 operations, EvilGrab formed part of a broader intrusion toolkit alongside malware such as ChChes and RedLeaves, with use against managed service providers, Japanese organizations, and other espionage targets. Its functionality and operational role are consistent with a collection-oriented espionage implant designed to establish access, monitor victims, and support follow-on compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The title of the lure was “2016年台灣總統選舉觀戰團 行程20160105.xls” which translates to “2016 Taiwan president election watching group schedule”. Once the spreadsheet is opened, CVE-2012-0158 is exploited and a file called 6EC5.tmp is dropped in the %TEMP% folder. | We have observed the EvilGrab, ChChes and RedLeaves malware families used as the primary method for initial exploitation to gain entry to the victim... EvilGrab, as per its name, has the capability to “grab” audio, video and screenshots of infected hosts and send the captured media to command and control servers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We have observed the EvilGrab, ChChes and RedLeaves malware families used as the primary method for initial exploitation to gain entry to the victim... EvilGrab, as per its name, has the capability to “grab” audio, video and screenshots of infected hosts and send the captured media to command and control servers.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
It attempts to inject into running processes, focussing on security products and native Windows processes.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that persists by adding a Registry Run key masquerading as ctfmon.exe.
Remote access trojan with screenshot capture capability.
Remote access trojan with screenshot capture capability.
Remote access trojan that persists by adding a Run key masquerading as ctfmon.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.