Evilnum__2020__Prevailion_Blog_Phantom_in_the_Command_Shell.pdf
ID: 413dac37-8422-485f-8a5c-f7173272db61
STIX ID: report--413dac37-8422-485f-8a5c-f7173272db61
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2020-07-10
Last Modified Date: 2020-07-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Prevailion observed a targeted campaign against financial organizations using EVILNUM variants (v3.6 and v4.0) delivered via Google Drive-hosted ZIPs with trojanized .lnk files; a headless JavaScript “Phantom” agent executes on Windows to enumerate systems, adapt persistence and C2 selection based on detected antivirus, steal cookies and exfiltrate data, and supports fetching secondary payloads. The report provides delivery and loader details, C2 retrieval via GitLab/DigitalPoint, C2 IP addresses, registry persistence changes, multiple file/script hashes, actor-created folders, and MITRE ATT&CK mappings.
