Also known as: EncryptHub, aka Larva-208, Evil Corp, tracked as, ZDI-25-150, Larva-148, manage hosting, set up the infrastructure, Water Gamayun, GOLD DRAKE
Larva-208 employs a sophisticated blend of social engineering and software exploitation to infiltrate corporate networks. Initial access is largely achieved through spear‑phishing emails that deliver malicious MSI installers or Base64‑encoded PowerShell scripts; once executed, the malware harvests credentials via multiple stealer modules (EncryptHub, Lumma, Amadey) and exfiltrates sensitive data over encrypted C&C channels. A key aspect of the actor’s technique is the exploitation of CVE‑2025‑26633, known as “MSC EvilTwin,” which allows an attacker to craft a .msc file that masquerades as legitimate Windows system components. By creating deceptive directories such as \Windows\System32 and \Windows\System32\en‑US, the malware achieves persistence, bypasses some defensive controls, and can re‑inject malicious code into unsuspecting users. Subsequent stages involve deploying custom backdoors SilentPrism and DarkWisp to maintain long‑term access and facilitate lateral movement. The actor’s command‑and‑control infrastructure is situated at 82.115.223.182 and may also be reachable via the encrypthub.net domain family. The combination of phishing, zero‑day exploitation, credential theft, and persistent backdoors results in frequent ransomware events and data loss for victims.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Larva-208, also known as EncryptHub or Water Gamayun, is a financially motivated threat actor that has attacked at least 618 organizations since June 2024. The group combines spear‑phishing campaigns with a zero‑day vulnerability (CVE‑2025‑26633) in the Microsoft Management Console to gain privilege and deploy ransomware. Their operations target high‑value sectors such as financial services, defense, and critical infrastructure across Russia, the United States and Iran.
Goals & Targeting
Larva-208’s strategic objective is financial gain through ransomware extortion and illicit monetization of stolen credentials. It targets financially lucrative sectors—particularly banking, defense contractors, and critical infrastructure providers—in Russia, the United States, and Iran. By leveraging a high‑impact zero‑day flaw and targeting organizations that manage sensitive data or national security assets, the actor maximizes leverage in negotiations while maintaining plausible deniability through low visibility phishing vectors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its emergence in mid‑2024, Larva-208 has executed a high‑volume campaign that impacts more than 600 organizations worldwide. It utilizes spear‑phishing as the main initial vector, coupling it with a zero‑day flaw to achieve persistence. Victims are primarily drawn from finance, defense and critical infrastructure—segments where a ransomware payoff is most enticing. The actor often updates its tools rapidly, shifting from domain‑hosted C&C to IP‑based servers (e.g., 82.115.223.182) to evade detection, while maintaining a tight operational tempo that allows frequent new infections before defenders can remediate patches for CVE‑2025‑26633.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a coherent picture of Larva‑208’s tactics, but gaps remain regarding precise operational timelines and full breadth of infrastructure. Much of the analysis derives from public advisories and malware samples that link several capabilities and tools together; however, attribution to specific campaigns across all targeted regions is not fully confirmed. Overall confidence is moderate, pending corroboration from additional internal or third‑party threat feeds.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
52
Tools
0
Campaigns
52
IOCs
0
Observed Data
1
Tactics