Threat group.View on attack.mitre.org
Evilnum is a financially motivated threat group that has been active since at least 2018.
| Technique | Procedure example |
|---|---|
| T1059.007 JavaScript |
Evilnum has used malicious JavaScript files on the victim's machine. |
| T1070.004 File Deletion |
Evilnum has deleted files used during infection. |
| T1105 Ingress Tool Transfer |
Evilnum can deploy additional components or tools as needed. |
| T1204.001 Malicious Link |
Evilnum has sent spearphishing emails designed to trick the recipient into opening malicious shortcut links which downloads a .LNK file. |
| T1219.002 Remote Desktop Software |
EVILNUM has used the malware variant, TerraTV, to run a legitimate TeamViewer application to connect to compromised machines. |
| T1497.001 System Checks |
Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments. |
| T1539 Steal Web Session Cookie |
Evilnum can steal cookies and session information from browsers. |
| T1548.002 Bypass User Account Control |
Evilnum has used PowerShell to bypass UAC. |
| T1555 Credentials from Password Stores |
Evilnum can collect email credentials from victims. |
| T1566.002 Spearphishing Link |
Evilnum has sent spearphishing emails containing a link to a zip file hosted on Google Drive. |
| T1574.001 DLL |
Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.