Evilnum

G0120

Threat group.View on attack.mitre.org

About this group

Evilnum is a financially motivated threat group that has been active since at least 2018.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1059.007
JavaScript

Evilnum has used malicious JavaScript files on the victim's machine.

T1070.004
File Deletion

Evilnum has deleted files used during infection.

T1105
Ingress Tool Transfer

Evilnum can deploy additional components or tools as needed.

T1204.001
Malicious Link

Evilnum has sent spearphishing emails designed to trick the recipient into opening malicious shortcut links which downloads a .LNK file.

T1219.002
Remote Desktop Software

EVILNUM has used the malware variant, TerraTV, to run a legitimate TeamViewer application to connect to compromised machines.

T1497.001
System Checks

Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments.

T1539
Steal Web Session Cookie

Evilnum can steal cookies and session information from browsers.

T1548.002
Bypass User Account Control

Evilnum has used PowerShell to bypass UAC.

T1555
Credentials from Password Stores

Evilnum can collect email credentials from victims.

T1566.002
Spearphishing Link

Evilnum has sent spearphishing emails containing a link to a zip file hosted on Google Drive.

T1574.001
DLL

Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder.

Software3

Campaigns0

None recorded.

References1

  1. ESET EvilNum July 2020 Open source
    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.