logo

Evilnum APT returns with updated TTPs and New Targets

ID: 9ebf2c4e-e061-5a6a-bacd-7216c2329408

STIX ID: report--9ebf2c4e-e061-5a6a-bacd-7216c2329408

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details a technical analysis of an Evilnum APT campaign targeting FinTech and related organizations in the UK and Europe. The threat actor uses spear-phishing with malicious Word documents (VBA code-stomping) to fetch an obfuscated JavaScript dropper, which writes a loader and encrypted payloads; the loader uses Heaven's Gate and a custom on-disk format to map a backdoor in memory. The backdoor supports C2 communication, encrypted exfiltration, and persistence via scheduled tasks. The report provides IOCs (file hashes, domains, URIs, task names) and decryption/analysis details useful for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.