Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
Evilnum
ID: 8f1c5bd61fcc6f9b5a5ae55a289a775a90636
Cybercrime
Cybercriminal
Threat types: Intrusion, Financial Theft, Malware
Progress: 35%
Completeness: 28%
Freshness: 50%
Operation zone: UNKNOWN
Aliases
Limited alias preview
No aliases registered.
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
Evilnum is a financially motivated threat group that has been active since at least 2018. Ref: https://attack.mitre.org/groups/G0120/
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1059.007 | JavaScript | TA0002 |
|
| T1070.004 | File Deletion | TA0005 |
|
| T1204.001 | Malicious Link | TA0002 |
|
| T1219.002 | Remote Desktop Software | TA0011 |
|
| T1497.001 | System Checks | TA0005 TA0007 |
|
| T1548.002 | Bypass User Account Control | TA0004 TA0005 |
|
| T1566.002 | Spearphishing Link | TA0001 |
|
| T1574.001 | DLL | TA0003 TA0004 TA0005 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.