EVILNUM (Javascript)

First seen
2018-06-01 00:00:00
Malware type
backdoor, downloader
Family
Malware family
Profile updated
2026-07-07 12:57:59

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:gb country_code:es country_code:it

Context

According proofpoint, EvilNum is a backdoor that can be used for data theft or to load additional payloads. The malware includes multiple interesting components to evade detection and modify infection paths based on identified antivirus software.

Reports & references

  • ESET — More Evil Deep Look Evilnum Toolset (report)
  • Kaspersky — 98177 (report)
  • Kaspersky — 99204 (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Evilnum (report)
  • blog.prevailion.com — Phantom In Command Shell5 (report)
  • mp.weixin.qq.com — Rexbtbni2Zxj4H3U6Ofmmw (report)
  • zscaler.com — Return Evilnum Apt Updated Ttps And New Targets (report)
  • blog.nsfocus.net — Agentvxapt Evilnum (report)
  • Palo Alto Unit 42 — Cardinal Rat Sins Again Targets Israeli Fin Tech Firms (report)
  • github.com — Evilnum (report)
  • pwncode.io — Javascript Based Bot Using Github C (report)
  • clearskysec.com — Clearsky 2019 H1 Cyber Events Summary Report (report)

External references