Evilnum APT returns with updated TTPs and New Targets
ID: 9ebf2c4e-e061-5a6a-bacd-7216c2329408
STIX ID: report--9ebf2c4e-e061-5a6a-bacd-7216c2329408
Feed Name: Zscaler Security Research Blog
This report details a technical analysis of an Evilnum APT campaign targeting FinTech and related organizations in the UK and Europe. The threat actor uses spear-phishing with malicious Word documents (VBA code-stomping) to fetch an obfuscated JavaScript dropper, which writes a loader and encrypted payloads; the loader uses Heaven's Gate and a custom on-disk format to map a backdoor in memory. The backdoor supports C2 communication, encrypted exfiltration, and persistence via scheduled tasks. The report provides IOCs (file hashes, domains, URIs, task names) and decryption/analysis details useful for detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
