EvilExtractor was observed in phishing campaigns as a Windows-focused info stealer that collects browser cookies, history, cached passwords, system details, Wi-Fi data, screenshots, selected files, keystrokes, and webcam captures from infected hosts. Researchers found the malware packaged in PyInstaller-based Python code or delivered through a .NET loader, with anti-analysis features including anti-VM, anti-sandbox, hostname checks, and date-based execution controls. Fortinet also reported that the malware family includes a ransomware component, Kodex Ransomware, which uses 7za.exe to create password-protected archives before dropping a ransom note.
Network analysis showed EvilExtractor operating autonomously after execution: it first checked the victim’s public IP, downloaded an additional archive named KK2023.zip from 193.42.33.232, and then connected to an attacker-controlled FTP server at 89.116.53.55 using hardcoded credentials to upload stolen data while preserving the victim’s directory structure. Additional modules, including Confirm.zip and MnMs.zip, were later retrieved to enable keylogging and webcam capture, and one observed execution also exfiltrated the malware archive itself from the victim desktop. Researchers said most observed victims were in Europe and the Americas and published related IOCs including infrastructure details and file hashes.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs observed EvilExtractor being distributed in a phishing email campaign on 30 March using an attachment disguised as an account confirmation file with an Adobe PDF icon. One observed payload was the PyInstaller-packed executable Account_Info.exe.
FortiGuard Labs observed a significant increase in malicious activity tied to evilextractor[.]com in March 2023, indicating broader operational use of the malware infrastructure.
A later ANY.RUN execution of the same EvilExtractor sample showed similar theft behavior and additionally exfiltrated the archive vv9wvsfb2v_pw_infected.zip, which contained the malware executable itself.
In the analyzed execution, EvilExtractor connected to FTP server 89.116.53.55 with hardcoded credentials and uploaded browser cookies, history, cached passwords, system details, Wi-Fi data, and selected files. The malware created victim-specific directories and preserved the local folder structure on the FTP server.
A sandbox PCAP analyzed by Netresec showed EvilExtractor checking the victim's public IP, downloading KK2023.zip from 193.42.33.232, and later retrieving Confirm.zip and MnMs.zip. The downloaded components were identified as browser-data theft, keylogger, and webcam modules.
FortiGuard Labs published analysis describing EvilExtractor as a Windows-focused info stealer used in phishing campaigns, with anti-analysis checks, FTP-based exfiltration, and an included Kodex Ransomware capability. The report also published infrastructure and file indicators.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.