TF-MAL-js.evilnum
📛 Threat Title
Malware family: EVILNUM
Description
ThreatFox malware family `js.evilnum`. Printable name: EVILNUM.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.evilnum
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.evilnum
IOC database
- Type
- domain
- Value
js.evilnum- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.evilnum
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.evilnum
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Threat Group Cards: A Threat Actor Encyclopedia APT group: Evilnum ... Last change to this card: 16 August 2025 Download this actor card in PDF or JSON format Previous: Evil Eye Next: FamousSparrow ↑
-
web:attack.mitre.org
Evilnum is a financially motivated threat group that has been active since at least 2018. [1]
-
web:github.com
Indicators of Compromises (IOC) of our various investigations - eset/ malware -ioc
-
web:incidentbuddy.ai
Threat profile for Evilnum (Ransomware Gang). 11 MITRE ATT&CK techniques mapped. See affected software and security gaps.
-
web:intel.mjolnirsecurity.com
Evilnum Threat Profile Financially motivated group targeting fintech and cryptocurrency companies with JavaScript-based malware and social engineering.
-
web:kcm.trellix.com
The APT group behind the Evilnum malware has been seen since 2018 in attacks against financial technology companies. The group's targets remain FinTech companies, but its tools and procedures used have evolved over time.
-
web:malpedia.caad.fkie.fraunhofer.de
ESET has analyzed the operations of Evilnum , the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While said malware has been seen in the wild since at least 2018 and documented previously, little has been published about the group behind it and how it operates. The group's targets remain fintech companies, but its toolset and ...
-
web:www.eset.com
Bratislava; Montreal, July 09, 2020 - ESET researchers are releasing their in-depth analysis into the operations of Evilnum , the APT group behind the Evilnum malware . According to ESET's telemetry, the targets are financial technology companies - for example, platforms and tools for online trading.
-
web:www.securityscientist.net
12 Questions and Answers About Evilnum (G0120) Evilnum (G0120) is a financially motivated APT group targeting fintech companies since 2018. Learn their TTPs, tools, detection techniques, and defence strategies. Evilnum (G0120) is a financially motivated threat group that has been quietly targeting fintech companies since at least 2018. They fly under the radar — not because they're ...
-
web:www.sisainfosec.com
Evilnum (APT TA4563) is a hacking group that has been active since at least 2018. This group primarily targets financial institutions, particularly those that use fintech platforms. Evilnum is known for using a variety of tactics to carry out their attacks, including social engineering, spear-phishing, and malware .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.