logo

Evilnum__2020__No_Rest_for_the_Wicked_Evilnum_Unleashes_PyVil_RAT.pdf

ID: b0978212-f37d-440f-915e-999114b05291

STIX ID: report--b0978212-f37d-440f-915e-999114b05291

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2020-09-07

Last Modified Date: 2020-09-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary Cybereason Nocturnus documents Evilnum's evolved campaign targeting FinTech organizations using spearphishing with KYC-themed attachments: an LNK dropper writes a JS dropper that installs a scheduled-task-based chain (ddpp.exe → fplayer.exe) which fetches and executes a py2exe-packed Python RAT called PyVil. PyVil supports keylogging, screenshots, credential theft (including a custom LaZagne module), remote shell, plugin/module updates via RC4-encrypted HTTP POSTs to multiple domains, and uses modified legitimate executables for stealth; the report includes detailed TTPs and IOCs for detection and response.