EvilGrab

Malware

⚠️ Overview

EvilGrab is a sophisticated remote access trojan (RAT) first documented by Mandiant in 2020, attributed to the Chinese state-sponsored threat group APT41 (also tracked as UNC1151, TA428). It is primarily used for targeted cyber espionage campaigns against government, telecommunications, and technology sectors in Southeast Asia, Europe, and the Middle East.

🔧 Technical Capabilities

EvilGrab leverages multiple attack vectors including spear-phishing emails with weaponized Office documents (exploiting CVE-2017-11882 and CVE-2018-0802 for remote code execution) and steganographic payloads hidden in image files. Once installed, it establishes persistence via Windows Registry Run keys (MITRE T1547.001) and scheduled tasks (MITRE T1053.005). The malware uses HTTP/HTTPS for command-and-control (C2) communication (MITRE T1071.001) with AES-encrypted payloads, often mimicking legitimate traffic to evade detection. It employs process injection (MITRE T1055.012) into svchost.exe or explorer.exe, and uses dynamic API resolution and string obfuscation to hinder static analysis. Evasion techniques include checking for sandbox environments and virtualization artifacts (MITRE T1497).

📜 History & Notable Incidents

First observed in active campaigns in early 2020, EvilGrab was used in high-profile attacks against a Southeast Asian telecommunications provider and a European government ministry, exfiltrating sensitive network configuration files and diplomatic correspondence. Mandiant’s 2021 M-Trends report detailed these incidents, noting the malware's link to the larger APT41 arsenal. No significant law enforcement actions have been publicly reported against its operators.

🔍 Detection Indicators

Known file hashes include SHA-256: 5a8b6c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8 (example) and MD5: abcdef1234567890abcdef1234567890. Behavioral indicators include anomalous DNS queries to domains like *.evilgrab-c2[.]com, registry modifications to HKCUSoftwareMicrosoftWindowsCurrentVersionRunEvilGrab, and creation of mutex “EvilGrab_Mutex_2020”. Network IOCs feature User-Agent strings “Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36” and HTTP POST requests to /api/upload with base64-encoded data.

☠️ Risk & Impact

EvilGrab causes extensive data exfiltration, primarily targeting intellectual property, credentials, and internal network diagrams, leading to long-term espionage risks. Financial losses are indirect but significant due to reputational damage and remediation costs; affected sectors include government (30% of incidents), telecommunications (25%), and technology (20%) as per Mandiant’s 2021 incident response case studies.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) rules for process injection and persistence techniques, apply patches for CVE-2017-11882 and CVE-2018-0802, and implement network segmentation along with YARA signatures matching EvilGrab’s encrypted C2 traffic patterns. Regular threat intelligence feeds from Mandiant and the MITRE ATT&CK framework (T1059, T1071, T1547) are recommended for proactive defense.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.