Evilnum
Also reported as DeathStalker, Jointworm, TA4563, EvilNum, KNOCKOUT SPIDER and 2 other names.
Reports per quarter
Techniques seen in the last two years
- T1005 1 report reports only
- T1041 1 report reports only
- T1070 1 report reports only
- T1074 1 report reports only
- T1102 1 report reports only
- T1105 1 report in ATT&CK
- T1112 1 report reports only
- T1204 1 report reports only
- T1539 1 report in ATT&CK
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-2938
- CVE-2008-3431 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-7248
Show all 55 CVEs Show fewer
- CVE-2015-7254
- CVE-2017-0261 KEV
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12611
- CVE-2017-5638 KEV ransomware
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-8453 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-15126
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-1664
- CVE-2020-3702
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2021-28550 KEV
- CVE-2021-31199 KEV
- CVE-2021-31201 KEV
- CVE-2021-31979 KEV
- CVE-2021-33771 KEV
- CVE-2021-36948 KEV
- CVE-2021-44515 KEV
- CVE-2022-22047 KEV
- CVE-2022-2294 KEV ransomware
- CVE-2022-33891 KEV
- CVE-2023-36025 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2024-21412 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
-
Phantom in the Command Shell - Prevailion
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Phantom in the Command Shell - Prevailion
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor More_eggs (Malware Family)
Show all 87 reports Show fewer
-
CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unmasking Venom Spider
-
DeathStalker targets legal entities with new Janicab variant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeathStalker targets legal entities with new Janicab variant
-
The original link failed its last check. Original publisher Detailsfor Evilnum%20IOCs.pdf
-
VileRAT- DeathStalker’s continuous strike at foreign and cryptocurrency exchanges
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VileRAT- DeathStalker’s continuous strike at foreign and cryptocurrency exchanges
-
The original link failed its last check. Original publisher Detailsfor PowerPoint Presentation
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities
-
Return of the Evilnum APT with updated TTPs and new targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Return of the Evilnum APT with updated TTPs and new targets
-
Janicab Series- Attibution and IoCs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Janicab Series- Attibution and IoCs
-
Operation DarkCasino- In-Depth Analysis of Recent Attacks by APT Group EVILNUM
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation DarkCasino- In-Depth Analysis of Recent Attacks by APT Group EVILNUM
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hackers Spearphish Corporate Hiring Managers with Poisoned Resumes, Infecting Them with the More_Eggs Malware, Warns eSentire
-
Mercenary APTs – An Exploration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mercenary APTs – An Exploration
-
Drawing a Dragon- Connecting the Dots to Find APT41
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Drawing a Dragon- Connecting the Dots to Find APT41
-
Evilnum organizes recent attacks against European financial companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evilnum organizes recent attacks against European financial companies
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Prevailion Blog
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hackers Spearphish Professionals on LinkedIn with Fake Job Offers, Infecting them with Malware, Warns eSentire
-
Terraloader- Congrats, you have a new fake job!
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Terraloader- Congrats, you have a new fake job!
-
DeathStalker Hits the Americas & Europe With New PowerPepper Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeathStalker Hits the Americas & Europe With New PowerPepper Malware
-
What did DeathStalker hide between two ferns-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What did DeathStalker hide between two ferns-
-
APT_trends_report_Q3_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q3_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Evilnum IOCs
-
No Rest for the Wicked_ Evilnum Unleashes PyVil RAT
The link to CyberMonitor archive on GitHub failed its last check. CyberMonitor archive on GitHub Detailsfor No Rest for the Wicked_ Evilnum Unleashes PyVil RAT
-
No Rest for the Wicked- Evilnum Unleashes PyVil RAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor No Rest for the Wicked- Evilnum Unleashes PyVil RAT
-
Lifting the veil on DeathStalker, a mercenary triumvirate _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lifting the veil on DeathStalker, a mercenary triumvirate _ Securelist
-
Lifting the veil on DeathStalker, a mercenary triumvirate
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lifting the veil on DeathStalker, a mercenary triumvirate
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
Kaspersky- New hacker-for-hire mercenary group is targeting European law firms
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kaspersky- New hacker-for-hire mercenary group is targeting European law firms
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Evilnum — Indicators of Compromise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evilnum — Indicators of Compromise
-
More evil- A deep look at Evilnum and its toolset
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More evil- A deep look at Evilnum and its toolset
-
More evil_ A deep look at Evilnum and its toolset _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor More evil_ A deep look at Evilnum and its toolset _ WeLiveSecurity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor IoCs
-
Prevailion Blog_ Phantom in the Command Shell
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Prevailion Blog_ Phantom in the Command Shell
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Phantom in the Command Shell
-
Cardinal RAT Sins Again, Targets Israeli Fin-Tech Firms
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cardinal RAT Sins Again, Targets Israeli Fin-Tech Firms
-
Software Description- More_eggs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Software Description- More_eggs
Newest first. Details opens the report in Explore.