Evilnum__2020__More_evil_A_deep_look_at_Evilnum_and_its_toolset_WeLiveSecurity.pdf
ID: 859be14d-7df1-46f0-bb85-bc2652b24e1d
STIX ID: report--859be14d-7df1-46f0-bb85-bc2652b24e1d
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2020-07-10
Last Modified Date: 2020-07-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's analysis profiles the Evilnum APT targeting fintech companies: attackers use spearphishing ZIPs containing double-extension LNKs that drop a malicious JavaScript first-stage which can deploy a C# backdoor (Evilnum) and additional tools. The group combines custom components and Malware‑as‑a‑Service (Golden Chickens) payloads (TerraLoader family, TerraPreter/Meterpreter, TerraStealer, TerraTV) to steal credentials, cookies, customer documents and enable stealthy remote access; the report includes IoCs and MITRE ATT&CK mappings.
