logo

Evilnum__2020__More_evil_A_deep_look_at_Evilnum_and_its_toolset_WeLiveSecurity.pdf

ID: 859be14d-7df1-46f0-bb85-bc2652b24e1d

STIX ID: report--859be14d-7df1-46f0-bb85-bc2652b24e1d

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2020-07-10

Last Modified Date: 2020-07-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's analysis profiles the Evilnum APT targeting fintech companies: attackers use spearphishing ZIPs containing double-extension LNKs that drop a malicious JavaScript first-stage which can deploy a C# backdoor (Evilnum) and additional tools. The group combines custom components and Malware‑as‑a‑Service (Golden Chickens) payloads (TerraLoader family, TerraPreter/Meterpreter, TerraStealer, TerraTV) to steal credentials, cookies, customer documents and enable stealthy remote access; the report includes IoCs and MITRE ATT&CK mappings.