The Evilnum threat group updated its long-running intrusions against UK and European organizations by overhauling both delivery and post-compromise tooling, with researchers linking the activity to targeted attacks on FinTech firms and later an intergovernmental organization involved in migration services. Earlier campaigns abused KYC-themed spearphishing and malicious .lnk files disguised as PDFs, while later operations shifted to malicious Word documents using template injection, VBA stomping, and heavily obfuscated JavaScript to launch a multi-stage infection chain. Across the campaigns, Evilnum increasingly relied on masquerading techniques, including modified legitimate Oracle and Nvidia executables, fake update installers, and themed domains designed to blend into victim environments.
The malware stack also evolved, culminating in the deployment of a Python-based remote access trojan known as PyVil RAT. Reporting and IOC data show Evilnum using staged JavaScript, .NET, Python, and OCX-based components, rotating command-and-control infrastructure, and persistence via scheduled tasks rather than older Run registry key methods. PyVil and related payloads support keylogging, screenshots, command execution, SSH shell access, credential theft, and additional module downloads, including a custom LaZagne variant for stealing passwords and cookies, while associated infrastructure has included impersonation domains, GitLab and forum-style URLs, and code-signing artifacts tied to some payloads.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
In March 2022, Evilnum targeted an intergovernmental organization involved in international migration services, expanding beyond its predominant FinTech victim set. The campaign's timing coincided with the Russia-Ukraine conflict.
In the newer campaigns observed from early 2022, Evilnum moved from LNK-in-ZIP phishing to malicious Microsoft Word documents using template injection, VBA code stomping, and obfuscated JavaScript to deploy its malware chain.
ThreatLabz reported that it had been monitoring Evilnum APT activity since the beginning of 2022, observing several low-volume targeted campaigns in the UK and Europe.
A February 2021 update to ESET Research's Evilnum IOC repository added new indicators for Evilnum and Pyvil, including detection of Python/Pyvil.A and Win32/GitBot.A.
The Evilnum threat group has been active since 2018, primarily targeting FinTech companies in the UK and other EU countries using spear-phishing lures themed around KYC documents.
Cybereason's Nocturnus team documented a newer Evilnum infection chain in which a PDF-themed LNK in a ZIP archive drops JavaScript loaders, modified Oracle and Nvidia executables, and a final Python-based RAT dubbed PyVil RAT. The report also noted a shift in persistence from Run registry keys to scheduled tasks and expanding command-and-control infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 261 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcecybereason.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.