EVILNUM (Windows)

First seen
2018-06-01 00:00:00
Malware type
trojan, credential-stealer, spyware
Family
Malware family
Profile updated
2026-07-07 12:57:57

Targeted industries: financial-services

Targeted regions: country_code:gb country_code:es

Context

EVILNUM is a malware family that primarily targets the financial services sector, often aiming to steal credentials and financial data. It is known for its spyware capabilities and has been active since at least 2018, primarily affecting regions in Europe.

Reports & references

  • ESET — More Evil Deep Look Evilnum Toolset (report)
  • proofpoint.com — Buy Sell Steal Evilnum Targets Cryptocurrency Forex Commodities (report)
  • zscaler.com — Return Evilnum Apt Updated Ttps And New Targets (report)
  • Palo Alto Unit 42 — Cardinal Rat Sins Again Targets Israeli Fin Tech Firms (report)
  • github.com — Evilnum (report)
  • stairwell.com — Technical Analysis The Silent Torrent Of Vilerat (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Evilnum (report)
  • web.archive.org — Phantom In Command Shell5 (report)
  • mp.weixin.qq.com — Lryl3A65Uiz1Awzcfuzp1A (report)
  • Broadcom/Symantec — Ransom And Malware Attacks On Financial Services Institutions (report)

External references