AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Evilnum
Aliases: None listed
Evilnum is a financially motivated threat group that has been active since at least 2018.
Open interactive actor investigation
ATT&CK techniques
T1497.001
System ChecksT1219
Remote Access SoftwareT1539
Steal Web Session CookieT1566.002
Spearphishing LinkT1548.002
Bypass User Account ControlT1070.004
File DeletionT1574.001
DLL Search Order HijackingT1204.001
Malicious LinkT1555
Credentials from Password StoresT1105
Ingress Tool TransferT1059.007
JavaScript
System ChecksT1219
Remote Access SoftwareT1539
Steal Web Session CookieT1566.002
Spearphishing LinkT1548.002
Bypass User Account ControlT1070.004
File DeletionT1574.001
DLL Search Order HijackingT1204.001
Malicious LinkT1555
Credentials from Password StoresT1105
Ingress Tool TransferT1059.007
JavaScript