Threat Actor Unknown origin
Evilnum
Also known as: DeathStalker · TA4563 · EvilNum · Jointworm · KNOCKOUT SPIDER
ESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While said malware has been seen in the wild since at least 2018 and documented previously, little has been published about the group behind it and how it operates. The group’s targets remain fintech companies, but its toolset and infrastructure have evolved and now consist of a mix of custom, homemade malware combined with tools purchased from Golden Chickens, a Malware-as-a-Service (MaaS) provider whose infamous customers include FIN6 and Cobalt Group.
MITRE ATT&CK TTPs 16
T1003 T1005 T1021 T1040 T1056.001 T1059 T1059.001 T1070.004 T1071.001 T1074 T1082 T1083 T1110 T1123 T1203 T1566
OS Credential Dumping
Credential Access
Data from Local System
Collection
Remote Services
Lateral Movement
Network Sniffing
Credential Access
Keylogging
Collection
Command and Scripting Interpreter
Execution
PowerShell
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
Data Staged
Collection
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Brute Force
Credential Access
Audio Capture
Collection
Exploitation for Client Execution
Execution
Phishing
Initial Access