EvilGrab

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[EvilGrab](https://attack.mitre.org/software/S0152) is a malware family with common reconnaissance capabilities. It has been deployed by [menuPass](https://attack.mitre.org/groups/G0045) via malicious Microsoft Office documents as part of spearphishing campaigns. (Citation: PWC Cloud Hopper Technical Annex April 2017)

Associated Techniques (5)
ID ATT&CK Tactics
T1056.001 Keylogging -
T1113 Screen Capture -
T1123 Audio Capture -
T1125 Video Capture -
T1547.001 Registry Run Keys / Startup Folder -
Used by Actors (1)
Metadata
ID: 121
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00