← Back to Pulse Feed
PULSE DETAIL
Since late 2021 through the present, Proofpoint Threat Research observed the group Proofpoint calls TA4563 targeting various European financial and investment entities with the malware known as EvilNum. The actor exclusively targeted entities in the Decentralized Finance (DeFi) industry in recently observed campaigns. The identified campaigns delivered an updated version of the EvilNum backdoor using a varied mix of ISO, Microsoft Word and Shortcut (LNK) files in late 2021 and early 2022, presumably as a method of testing the efficacy of the delivery methods. This malware can be used for reconnaissance, data theft, and to deploy additional payloads.
MITRE ATT&CK & Malware Families
Indicators of Compromise (1 / 37 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | c73033ea7be3bb159c207c39e954ce18 | MD5 of f0a002c7d2174f2a022d0dfdb0d83973c1dd96c4db86a2b687d14561ab564daa | 2022-07-22 |