PULSE NAME
EvilNum Targets Cryptocurrency, Forex, Commodities
WHITE TA4563 AlienVault 2022-07-22 Modified: 2022-07-22
37
IOCs
MEDIUM VOLUME
Since late 2021 through the present, Proofpoint Threat Research observed the group Proofpoint calls TA4563 targeting various European financial and investment entities with the malware known as EvilNum. The actor exclusively targeted entities in the Decentralized Finance (DeFi) industry in recently observed campaigns. The identified campaigns delivered an updated version of the EvilNum backdoor using a varied mix of ISO, Microsoft Word and Shortcut (LNK) files in late 2021 and early 2022, presumably as a method of testing the efficacy of the delivery methods. This malware can be used for reconnaissance, data theft, and to deploy additional payloads.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
EvilNum
Indicators of Compromise (1 / 37 total)
All email URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 c73033ea7be3bb159c207c39e954ce18 MD5 of f0a002c7d2174f2a022d0dfdb0d83973c1dd96c4db86a2b687d14561ab564daa 2022-07-22