EVILNUM

S0568

Malware.View on attack.mitre.org

About this malware

EVILNUM is fully capable backdoor that was first identified in 2018. EVILNUM is used by the APT group Evilnum which has the same name.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1033
System Owner/User Discovery

EVILNUM can obtain the username from the victim's machine.

T1041
Exfiltration Over C2 Channel

EVILNUM can upload files over the C2 channel from the infected host.

T1047
Windows Management Instrumentation

EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines.

T1070
Indicator Removal

EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack.

T1070.006
Timestomp

EVILNUM has changed the creation date of files.

T1082
System Information Discovery

EVILNUM can obtain the computer name from the victim's system.

T1102.003
One-Way Communication

EVILNUM has used a one-way communication method via GitLab and Digital Point to perform C2.

T1105
Ingress Tool Transfer

EVILNUM can download and upload files to the victim's computer.

T1112
Modify Registry

EVILNUM can make modifications to the Regsitry for persistence.

T1218.010
Regsvr32

EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe.

T1218.011
Rundll32

EVILNUM can execute commands and scripts through rundll32.

T1518.001
Security Software Discovery

EVILNUM can search for anti-virus products on the system.

T1539
Steal Web Session Cookie

EVILNUM can harvest cookies and upload them to the C2 server.

T1547.001
Registry Run Keys / Startup Folder

EVILNUM can achieve persistence through the Registry Run key.

Groups that use it1

Campaigns0

None recorded.

References2

  1. ESET EvilNum July 2020 Open source
    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.
  2. Prevailion EvilNum May 2020 Open source
    Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.