G0120

EvilnumEvilnum

Also known as: DeathStalker · TA4563 · EvilNum · Jointworm · KNOCKOUT SPIDER

Known aliases
5

Profile

ESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While said malware has been seen in the wild since at least 2018 and documented previously, little has been published about the group behind it and how it operates. The group’s targets remain fintech companies, but its toolset and infrastructure have evolved and now consist of a mix of custom, homemade malware combined with tools purchased from Golden Chickens, a Malware-as-a-Service (MaaS) provider whose infamous customers include FIN6 and Cobalt Group.

Aliases· 5

DeathStalkerTA4563EvilNumJointwormKNOCKOUT SPIDER

MITRE ATT&CK Group crosswalk

G0120

References

  1. https://www.welivesecurity.com/2020/07/09/more-evil-deep-look-evilnum-toolset/
  2. https://securelist.com/deathstalker-mercenary-triumvirate/98177/
  3. https://securelist.com/what-did-deathstalker-hide-between-two-ferns/99616/
  4. https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities
  5. https://www.rewterz.com/rewterz-news/rewterz-threat-alert-evilnum-apt-group-active-iocs-7
  6. https://www.rewterz.com/rewterz-news/rewterz-threat-alert-evilnum-apt-group-targeting-financial-sector
  7. https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf
  8. https://www.hivepro.com/wp-content/uploads/2022/08/Vulnerabilities-Threats-that-Matter-25th-to-31st-July.pdf

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
FIN11
Actor
EvilWeb
Actor
FIN1
Actor
Evil Corp
Actor
MUMMY SPIDER
Actor
APT41
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.