ATT&CKReferencesESET EvilNum July 2020

ESET EvilNum July 2020

Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMore_eggs

More_eggs's payload has been encrypted with a key that has the hostname and processor family information appended to the end.

T1059.003
Windows Command Shell
MalwareMore_eggs

More_eggs has used cmd.exe for execution.

T1059.007
JavaScript
GroupEvilnum

Evilnum has used malicious JavaScript files on the victim's machine.

T1070.004
File Deletion
GroupEvilnum

Evilnum has deleted files used during infection.

T1105
Ingress Tool Transfer
GroupEvilnum

Evilnum can deploy additional components or tools as needed.

T1105
Ingress Tool Transfer
MalwareEVILNUM

EVILNUM can download and upload files to the victim's computer.

T1204.001
Malicious Link
GroupEvilnum

Evilnum has sent spearphishing emails designed to trick the recipient into opening malicious shortcut links which downloads a .LNK file.

T1218.010
Regsvr32
MalwareEVILNUM

EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe.

T1219.002
Remote Desktop Software
GroupEvilnum

EVILNUM has used the malware variant, TerraTV, to run a legitimate TeamViewer application to connect to compromised machines.

T1497.001
System Checks
GroupEvilnum

Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments.

T1539
Steal Web Session Cookie
GroupEvilnum

Evilnum can steal cookies and session information from browsers.

T1547.001
Registry Run Keys / Startup Folder
MalwareEVILNUM

EVILNUM can achieve persistence through the Registry Run key.

T1548.002
Bypass User Account Control
GroupEvilnum

Evilnum has used PowerShell to bypass UAC.

T1555
Credentials from Password Stores
GroupEvilnum

Evilnum can collect email credentials from victims.

T1566.002
Spearphishing Link
GroupEvilnum

Evilnum has sent spearphishing emails containing a link to a zip file hosted on Google Drive.

T1574.001
DLL
GroupEvilnum

Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.