EvilPost is a sophisticated cyber threat actor primarily engaged in advanced persistent threats (APTs) targeting multiple sectors across various countries. The group's operations are characterized by the use of custom malware and exploitation of critical vulnerabilities. EvilPost is assessed with high confidence to be of Chinese origin, reflecting motivations aligned with intelligence gathering and strategic advantage for state interests. While they have been linked to numerous high-profile attacks, specific details defining their unique operational characteristics or structure evolution are not widely documented under this designation. They are often associated with activities similar to groups like APT29, Cozy Bear, and The Dukes, though these are considered related groups rather than direct aliases or structural evolutions of EvilPost.