Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:24:31 UTC Home > List all groups > List all tools > List all groups using tool Evilnum Tool: Evilnum Names Evilnum EVILNUM Marvel Category Malware Type Loader, Backdoor Description (ESET) This component communicates with a C&C server and acts as a backdoor without the need for any additional program. However, in most attacks that we have seen, the attackers deployed additional components as they saw fit and used the JS malware only as a first stage. The first known mention of this JavaScript malware was in May 2018 in this pwncode article. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool Evilnum Changed Name Country Observed https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=57ac4c19-94d8-4e6e-9240-f10c0e2e3940 Page 1 of 2 APT groups   Deceptikons, DeathStalker [Unknown] 2012-Jun 2020     Evilnum [Unknown] 2018-2022   2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=57ac4c19-94d8-4e6e-9240-f10c0e2e3940 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=57ac4c19-94d8-4e6e-9240-f10c0e2e3940 Page 2 of 2