AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Evilnum
Aliases: None listed
Evilnum is a financially motivated threat group that has been active since at least 2018.
Open interactive actor investigation
ATT&CK techniques
System ChecksT1219
Remote Access SoftwareT1539
Steal Web Session CookieT1566.002
Spearphishing LinkT1548.002
Bypass User Account ControlT1070.004
File DeletionT1574.001
DLL Search Order HijackingT1204.001
Malicious LinkT1555
Credentials from Password StoresT1105
Ingress Tool TransferT1059.007
JavaScript
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Vulnerability Research & Exploit Development · explicit-nameContainer image, registry, runtime, and host security
Cloud Security · topic-matchCryptography, secrets, and key lifecycle
Secure Code & Application Security · topic-matchPrivacy, secrets, confidential data, and model leakage
AI Security · topic-matchAI-generated code, RAG, models, agents, and MCP-connected tools
Secure Code & Application Security · topic-matchAI incident response and forensic readiness
AI Security · topic-matchModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-matchModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · topic-matchWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-matchModule 11 — Mobile and thick-client security
Red Team & Offensive Security · topic-matchModule 12 — Human-layer and physical testing
Red Team & Offensive Security · topic-matchThreat modeling and secure architecture
Secure Code & Application Security · topic-match