Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Larva-208

Also known as: EncryptHub, aka Larva-208, Evil Corp, tracked as, ZDI-25-150, Larva-148, manage hosting, set up the infrastructure, Water Gamayun, GOLD DRAKE

Description

Larva-208 employs a sophisticated blend of social engineering and software exploitation to infiltrate corporate networks. Initial access is largely achieved through spear‑phishing emails that deliver malicious MSI installers or Base64‑encoded PowerShell scripts; once executed, the malware harvests credentials via multiple stealer modules (EncryptHub, Lumma, Amadey) and exfiltrates sensitive data over encrypted C&C channels. A key aspect of the actor’s technique is the exploitation of CVE‑2025‑26633, known as “MSC EvilTwin,” which allows an attacker to craft a .msc file that masquerades as legitimate Windows system components. By creating deceptive directories such as \Windows\System32 and \Windows\System32\en‑US, the malware achieves persistence, bypasses some defensive controls, and can re‑inject malicious code into unsuspecting users. Subsequent stages involve deploying custom backdoors SilentPrism and DarkWisp to maintain long‑term access and facilitate lateral movement. The actor’s command‑and‑control infrastructure is situated at 82.115.223.182 and may also be reachable via the encrypthub.net domain family. The combination of phishing, zero‑day exploitation, credential theft, and persistent backdoors results in frequent ransomware events and data loss for victims.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Critical infrastructure

Targeted Countries / Regions

RU
US
IR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Larva-208, also known as EncryptHub or Water Gamayun, is a financially motivated threat actor that has attacked at least 618 organizations since June 2024. The group combines spear‑phishing campaigns with a zero‑day vulnerability (CVE‑2025‑26633) in the Microsoft Management Console to gain privilege and deploy ransomware. Their operations target high‑value sectors such as financial services, defense, and critical infrastructure across Russia, the United States and Iran.

Goals & Targeting

Larva-208’s strategic objective is financial gain through ransomware extortion and illicit monetization of stolen credentials. It targets financially lucrative sectors—particularly banking, defense contractors, and critical infrastructure providers—in Russia, the United States, and Iran. By leveraging a high‑impact zero‑day flaw and targeting organizations that manage sensitive data or national security assets, the actor maximizes leverage in negotiations while maintaining plausible deniability through low visibility phishing vectors.

Enhanced Description

Key Capabilities

  • Zero‑day exploitation of Microsoft Management Console via MSC EvilTwin (CVE‑2025‑26633) using crafted .msc files
  • Creation of deceptive system directories such as C:\\Windows\\System32 and C:\\Windows\\System32\\en-US for persistence and evasion
  • Deployment of malicious MSI installers and Base64‑encoded PowerShell stealers to harvest credentials
  • Use of backdoors SilentPrism and DarkWisp for long‑term access and lateral movement
  • Encrypted command‑and‑control channels to exfiltrate data and receive further payloads

MITRE ATT&CK Tactics

Execution
Persistence
Defense Evasion
Credential Access
Exfiltration

ATT&CK Techniques

T1059.001: PowerShell
T1204: User Execution
T1041: Exfiltration Over Command and Control Channel
T1547: Boot or Logon Autostart Execution
T1063: Permission Groups Discovery
T1110: Brute Force (Credential Access)
T1036.001: Masquerading – System Software Name
T1074: Data Staging

Software / Tooling

EncryptHub Stealer Variant A
EncryptHub Stealer Variant B
EncryptHub Stealer Variant C
SilentPrism backdoor
DarkWisp backdoor
MSC EvilTwin Loader
Stealc
Rhadamanthys Stealer
Kematian‑Stealer
Lumma Stealer
Amadey
skotes.exe
WEXTRACT.EXE.MUI
axplong.exe

Campaigns & Victims

Since its emergence in mid‑2024, Larva-208 has executed a high‑volume campaign that impacts more than 600 organizations worldwide. It utilizes spear‑phishing as the main initial vector, coupling it with a zero‑day flaw to achieve persistence. Victims are primarily drawn from finance, defense and critical infrastructure—segments where a ransomware payoff is most enticing. The actor often updates its tools rapidly, shifting from domain‑hosted C&C to IP‑based servers (e.g., 82.115.223.182) to evade detection, while maintaining a tight operational tempo that allows frequent new infections before defenders can remediate patches for CVE‑2025‑26633.

IOC Patterns

  • Domain: encrypthub.net
  • Domain: encrypthub.org
  • IP address: 82.115.223.182
  • File extension: .msc
  • MSI package delivery via signed executables (e.g., skotes.exe, WEXTRACT.EXE.MUI)
  • Directory paths: C:\Windows\System32 and C:\Windows\System32\en-US
  • CVE‑2025‑26633 zero‑day exploitation pattern
  • Encrypted PowerShell payloads (Base64 strings)

Recommended Actions

  • Apply the official Microsoft patch for CVE‑2025‑26633 immediately to block MSC EvilTwin attacks.
  • Block or filter outbound connections to 82.115.223.182 and the encrypthub.* domain family on firewalls and DNS filtering solutions.
  • Implement endpoint detection that flags creation of unauthorized .msc files and directories under System32, and alerts on execution of known malicious MSI installers.
  • Deploy EDR rules to detect SilentPrism (e.g., mmc.exe or invoker.exe patterns) and DarkWisp binaries. "
  • Ensure multi‑factor authentication is enforced across all user accounts to reduce the impact of credential theft.
  • Conduct targeted phishing awareness training for employees, focusing on spear‑phishing detection and safe handling of email attachments and links.
  • Segment networks to limit lateral movement from initial compromise points and monitor for unusual process execution under legitimate system directories.
  • Use network monitoring tools to identify encrypted C&C traffic or abnormal data staging activities indicative of exfiltration stages. "

Suggested Tags

Water Gamayun
EncryptHub
Larva‑208
Evil Corp
ZDI-25‑150
Russian threat actor
CVE‑2025‑26633
MSC EvilTwin Zero-Day
Backdoor
Stealer
PowerShell
Zero‑day Exploit
MSI Delivery
Encrypted C&C

Confidence Assessment

The available intelligence provides a coherent picture of Larva‑208’s tactics, but gaps remain regarding precise operational timelines and full breadth of infrastructure. Much of the analysis derives from public advisories and malware samples that link several capabilities and tools together; however, attribution to specific campaigns across all targeted regions is not fully confirmed. Overall confidence is moderate, pending corroboration from additional internal or third‑party threat feeds.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 1 Domain 11 MD5 Hash 3 SHA-1 Hash 3 SHA-256 Hash 2

References

  1. www.trendmicro.com — Cited by web research for: ZDI-25-150
  2. www.bleepingcomputer.com — Cited by web research for: Larva-148
  3. www.trendmicro.com — Cited by web research for: PowerShell
  4. www.ampcuscyber.com — Cited by web research for: CALENDAR

Intel Summary

8

Techniques

52

Tools

0

Campaigns

52

IOCs

0

Observed Data

1

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
APT
ransomware
phishing
financial-motivated
MFA-bypass
enterprise-targeted
Water Gamayun
EncryptHub
Larva‑208
Evil Corp
ZDI-25‑150
Russian threat actor
CVE‑2025‑26633
MSC EvilTwin Zero-Day
Backdoor
Stealer
PowerShell
Zero‑day Exploit
MSI Delivery
Encrypted C&C

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.