Also known as: EncryptHub, LARVA-208, Larva-208, tracked as, is a Russian, ZDI-25-150
Water Gamayun leverages the Microsoft Management Console zero‑day vulnerability (CVE-2025‑26633), also known as MSC EvilTwin, to inject malicious code into mmc.exe. The actor then deploys tightly obfuscated, multi‑stage PowerShell payloads that use Base64‑encoded strings and password‑protected archives to evade sandbox analysis and detection. Persistence is achieved through custom backdoors such as SilentPrism and DarkWisp, which establish long‑term footholds and allow dynamic command and control. Data exfiltration channels are typically encrypted, often using legitimate Windows protocols or custom SSL tunnels. The campaign also employs several credential and data stealers, including EncryptHub Stealer variants, Stealc, and Rhadamanthys. Delivery is diversified: signed Microsoft Installer (.msi) files, manipulated .msc resources via MUIPath, and Living‑Off‑the‑Land Binaries (LOLBins) are used for lateral movement and execution. This blend of zero‑day exploitation, sophisticated persistence, and stealthy exfiltration makes the actor a high‑risk target for organizations operating within its focus sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Water Gamayun is a financially motivated, likely Russian threat actor that advanced exploitation of the MS Excel 365 zero‑day CVE-2025-26633 (MSC EvilTwin) to deliver encrypted PowerShell payloads and persist via custom backdoors such as SilentPrism and DarkWisp. It employs signed MSI files, .msc file manipulation, and LOLBins for execution, targeting defense, financial services, government, utilities, and critical infrastructure in China, the United States, and Russia.
Goals & Targeting
The primary motivation is financial gain through data theft, ransomware deployment, or extortion. Water Gamayun selectively targets strategic sectors—defense, government, utilities, finance, and critical infrastructure—in jurisdictions that offer both economic value and opportunities to disrupt operations. The actor seeks high‑value, highly connected environments where compromised data can be leveraged for blackmail or leverage in broader geopolitical maneuvers.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Gamayun demonstrates a high-velocity, opportunistic operational tempo. It typically exploits zero‑day vulnerabilities for initial compromise, then layers obfuscation and persistence tools to maintain stealth. Victims are chosen from sectors with valuable data or critical services; the actor prefers environments where lateral movement can expand reach rapidly. Notable past operations include deployment against a US defense contractor using the MSC EvilTwin flaw and subsequent use of signed MSI files to deliver malicious shells. The actor’s campaigns have been observed to pivot quickly across domains, often changing C2 endpoints and leveraging legitimate protocols for exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence provided confirms the use of MSC EvilTwin (CVE‑2025‑26633) and specific backdoors, indicating strong confidence in these capabilities. While attribution to a Russian origin is supported by multiple analysts, details such as first/last seen dates and full campaign chronology remain incomplete, creating uncertainty around operational scope and lifecycle. Information gaps persist regarding the exact extent of exfiltration methods and whether ransomware has been deployed in all observed incidents.
No campaigns linked yet.
No observed data linked yet.
45
Techniques
42
Tools
0
Campaigns
54
IOCs
0
Observed Data
11
Tactics