EVILNUM

MITRE ATT&CK: S0568 View on attack.mitre.org

Aliases: EVILNUM

First seen
2018-01-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2025-02-17 01:39:44
Profile updated
2026-07-07 12:57:55

Targeted industries: financial-services

Context

EVILNUM is fully capable backdoor that was first identified in 2018. EVILNUM is used by the APT group Evilnum which has the same name.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to EVILNUM (S0568). The 1 most recently updated:

TypeIndicatorUpdatedSources
hostname kalpoipolpmi.net 2025-02-17 1

Detection coverage

  • 2 YARA rules
  • 368 Sigma rules

Malware & tools used

  • One-Way Communication (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Indicator Removal (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Timestomp (attack-pattern)
  • Modify Registry (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Rundll32 (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_APT_Evilnum_LNK_Jul_2021_1 (yara-rule)
  • SEKOIA_Evilnumpayload_Fmtstr (yara-rule)

Reports & references

  • ESET — More Evil Deep Look Evilnum Toolset (report)
  • MITRE ATT&CK — S0568 (report)
  • web.archive.org — Phantom In The Command Shell 2 (report)

External references