Threat Actor Profile
High APT
Description

Evilnum is a financially motivated threat group that has been active since at least 2018.(Citation: ESET EvilNum July 2020)

Confidence Score
90%
Known Aliases
Evilnum
Tags
mitre-attack stix-2.1 intrusion-set
First Seen

Unknown

Last Updated

Unknown

Active Status
Active
Created

April 29, 2026

MITRE ATT&CK Techniques (11)
T1105 - Ingress Tool Transfer
Command and Control
T1219.002 - Remote Desktop Software
Command and Control
T1539 - Steal Web Session Cookie
Credential Access
T1555 - Credentials from Password Stores
Credential Access
T1070.004 - File Deletion
Defense Evasion
T1497.001 - System Checks
Defense Evasion
T1059.007 - JavaScript
Execution
T1204.001 - Malicious Link
Execution
T1566.002 - Spearphishing Link
Initial Access
T1574.001 - DLL
Persistence
T1548.002 - Bypass User Account Control
Privilege Escalation
Indicators of Compromise

Loading IOCs…

IOC KQL for Sentinel
STIX Data
{'aliases': ['Evilnum'],
 'created': '2021-01-22T16:46:17.790Z',
 'created_by_ref': 'identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5',
 'description': '[Evilnum](https://attack.mitre.org/groups/G0120) is a '
                'financially motivated threat group that has been active since '
                'at least 2018.(Citation: ESET EvilNum July 2020)',
 'external_references': [{'external_id': 'G0120',
                          'source_name': 'mitre-attack',
                          'url': 'https://attack.mitre.org/groups/G0120'},
                         {'description': '(Citation: ESET EvilNum July 2020)',
                          'source_name': 'Evilnum'},
                         {'description': 'Porolli, M. (2020, July 9). More '
                                         'evil: A deep look at Evilnum and its '
                                         'toolset. Retrieved January 22, 2021.',
                          'source_name': 'ESET EvilNum July 2020',
                          'url': 'https://www.welivesecurity.com/2020/07/09/more-evil-deep-look-evilnum-toolset/'}],
 'id': 'intrusion-set--1f0f9a14-11aa-49aa-9174-bcd0eaa979de',
 'modified': '2025-04-25T14:49:26.766Z',
 'name': 'Evilnum',
 'object_marking_refs': ['marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168'],
 'spec_version': '2.1',
 'type': 'intrusion-set',
 'x_mitre_attack_spec_version': '3.2.0',
 'x_mitre_deprecated': False,
 'x_mitre_domains': ['enterprise-attack'],
 'x_mitre_modified_by_ref': 'identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5',
 'x_mitre_version': '1.0'}
Quick Actions
Related TTPs (11)
Ingress Tool Transfer
Command and Control

Remote Desktop Software
Command and Control

Steal Web Session Cookie
Credential Access

Credentials from Password Sto…
Credential Access

File Deletion
Defense Evasion