logo

Evilnum__2020__Lifting_the_veil_on_DeathStalker_a_mercenary_triumvirate_Securelist.pdf

ID: 9eaf4f3b-0e73-4311-a906-9ce15b2de4a8

STIX ID: report--9eaf4f3b-0e73-4311-a906-9ce15b2de4a8

Threat Score

70/100

Uploaded: 2026-08-14

Published Date: 2020-11-26

Last Modified Date: 2020-11-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Kaspersky blog analyzes the DeathStalker actor (aka Powersing), describing an LNK-based spear-phishing infection chain that launches multi-stage PowerShell/C#.NET implants which use public dead-drop resolvers to obtain cryptographic keys and C2 addresses, capture periodic screenshots, and execute arbitrary PowerShell; the report links Powersing to Janicab and Evilnum based on shared techniques and code artifacts and includes IoCs (file hashes and C2 IPs) and mitigation recommendations for defenders.