Evilnum__2020__Lifting_the_veil_on_DeathStalker_a_mercenary_triumvirate_Securelist.pdf
ID: 9eaf4f3b-0e73-4311-a906-9ce15b2de4a8
STIX ID: report--9eaf4f3b-0e73-4311-a906-9ce15b2de4a8
Threat Score
70/100
Uploaded: 2026-08-14
Published Date: 2020-11-26
Last Modified Date: 2020-11-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Kaspersky blog analyzes the DeathStalker actor (aka Powersing), describing an LNK-based spear-phishing infection chain that launches multi-stage PowerShell/C#.NET implants which use public dead-drop resolvers to obtain cryptographic keys and C2 addresses, capture periodic screenshots, and execute arbitrary PowerShell; the report links Powersing to Janicab and Evilnum based on shared techniques and code artifacts and includes IoCs (file hashes and C2 IPs) and mitigation recommendations for defenders.
