Evilnum

Also known as: DeathStalker, Decepticons, Evilnum, EvilNum, Jointworm, KNOCKOUT SPIDER, TA4563

Evilnum is a financially motivated threat group that has been active since at least 2018. ESET EvilNum July 2020

🧭 ATT&CK G0120

Introduction

Evilnum is a financially motivated threat group that has been active since at least 2018. ESET EvilNum July 2020

Activities and Tactics

Information pending cataloguing.

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • GOlden Phoenix
  • Cobalt Strike

MITRE ATT&CK Software

Attribution and Evidence

Information pending cataloguing.

References

[1] mitre-attack [3] ESET EvilNum July 2020 Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.