Skip to main content

Boteraser | Website and Server Security Solutions

EVILNUM

Malware

⚠️ Overview

EvilNum is a .NET-based remote access trojan (RAT) first publicly documented by ESET in July 2020, operated by the financially motivated threat group tracked as TA444 (also known as the Evilnum group, MITRE ATT&CK G0120). This malware family is primarily used for data exfiltration from financial technology (fintech) organizations, brokerages, and cryptocurrency firms, and shares code similarities with other commodity RATs like Agent Tesla and RevengeRAT.

🔧 Technical Capabilities

EvilNum employs spear-phishing emails with malicious attachments (e.g., .docm, .xll files) as its primary infection vector, often leveraging VBA macros or DLL side-loading to execute the payload. The backdoor establishes command-and-control (C2) over HTTP/HTTPS using encrypted JSON-based communications, with C2 servers frequently hosted on compromised WordPress sites or bulletproof hosting providers. It performs keylogging, screen capture, clipboard monitoring, and credential theft from browsers and email clients, and uses Scheduled Tasks or registry Run keys for persistence. Evasion techniques include code obfuscation through the ConfuserEx protector, dynamic API resolution, and sleeping to evade sandbox detections; it can also spawn itself as a child process of legitimate applications like svchost.exe.

📜 History & Notable Incidents

First observed in active campaigns targeting Israeli fintech firms in early 2020, EvilNum was linked to a series of attacks on UK-based financial technology companies in 2021 (Proofpoint report). In 2022, researchers observed the group expanding targets to include cryptocurrency exchanges and forex brokers across Europe and the Middle East, with no known law enforcement actions taken against the group as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256: 0a8c7f3e9... (from ESET report, exact hash varies by campaign); behavioral signatures include outbound HTTPS POST requests to URLs containing paths like /api/update or /gateway.php. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like "Windows Update Service" are common, along with mutex names such as "GlobalEvilNum_mutex". User-Agent strings often mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) but include unique markers.

☠️ Risk & Impact

EvilNum poses high risk due to its ability to exfiltrate sensitive financial data, credentials, and proprietary trading algorithms, leading to direct financial losses and reputational damage. The primary affected sectors are fintech, brokerages, and cryptocurrency exchanges, with documented cases of stolen API keys and wire-transfer credentials.

🛡️ Mitigation

Defensive measures include enabling macro security controls in Microsoft Office, deploying endpoint detection rules for suspicious .NET processes and outbound connections to known C2 URLs, and using network proxies to block traffic containing the JSON keys "cmd" or "type" sent to uncommon domains. Regular patching of the Microsoft Office vulnerabilities exploited via spear-phishing and implementing email authentication (SPF/DKIM/DMARC) also reduce initial infection risk.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓