evilnum hackers return in new operation targeting migration orgs

Home/IOC's, malicious cyber actors, Security Advisory, Security Update/evilnum hackers return in new operation targeting migration orgs

evilnum hackers return in new operation targeting migration orgs

The Evilnum hacking group have been targeting European organisations that are involved in international migration, showing renewed signs of malicious activity within the group.

Campaign Details

Zscaler’s analysts have discovered the latest exposure, having been tracking Evilnum’s activity since the beginning of 2022. They have captured various artefacts from the attacks.

The targeting and timing coincided with the Russian invasion of Ukraine, with key migration organisations receiving malicious emails containing macro-laden documents

The documents used by Evilnum in the campaign carry varying filenames, usually containing the term “compliance.” Zscaler identified at least nine different documents used, as mentioned in the IoC section of the report.

The attachment leverage the template injection and VBA code stomping technique to evade detection, leading to the execution of heavily obfuscated JavaScript.

Additionally, the backdoor captures machine snapshots and sends them to the C2 via POST requests, exfiltrating stolen data in an encrypted form.

This, in turn, decrypts and drops a malware loader (“SerenadeDACplApp.exe”) and an encrypted binary (“devZUQVD.tmp”), and also creates a scheduled task (“UpdateModel Task”) for persistence.

In addition, the backdoor is capable of capturing system snapshots and transmitting them to the C2 server via POST requests. This allows the data to be exfiltrated in an encrypted format.

File Hash

  • 0b4f0ead0482582f7a98362dbf18c219
  • 6d329140fb53a3078666e17c249ce112
  • db0866289dfded1174941880af94296f

Follow us for more, Facebook, Twitter, LinkedIn and Instagram

By | 2022-06-30T20:41:23+05:30 June 30th, 2022|IOC's, malicious cyber actors, Security Advisory, Security Update|

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!