Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Water Gamayun

Also known as: EncryptHub, LARVA-208, Larva-208, tracked as, is a Russian, ZDI-25-150

Description

Water Gamayun leverages the Microsoft Management Console zero‑day vulnerability (CVE-2025‑26633), also known as MSC EvilTwin, to inject malicious code into mmc.exe. The actor then deploys tightly obfuscated, multi‑stage PowerShell payloads that use Base64‑encoded strings and password‑protected archives to evade sandbox analysis and detection. Persistence is achieved through custom backdoors such as SilentPrism and DarkWisp, which establish long‑term footholds and allow dynamic command and control. Data exfiltration channels are typically encrypted, often using legitimate Windows protocols or custom SSL tunnels. The campaign also employs several credential and data stealers, including EncryptHub Stealer variants, Stealc, and Rhadamanthys. Delivery is diversified: signed Microsoft Installer (.msi) files, manipulated .msc resources via MUIPath, and Living‑Off‑the‑Land Binaries (LOLBins) are used for lateral movement and execution. This blend of zero‑day exploitation, sophisticated persistence, and stealthy exfiltration makes the actor a high‑risk target for organizations operating within its focus sectors.

Goals & Targeting

Targeted Sectors

Defense
Financial services
Government
Utilities
Critical infrastructure

Targeted Countries / Regions

CN
US
RU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Water Gamayun is a financially motivated, likely Russian threat actor that advanced exploitation of the MS Excel 365 zero‑day CVE-2025-26633 (MSC EvilTwin) to deliver encrypted PowerShell payloads and persist via custom backdoors such as SilentPrism and DarkWisp. It employs signed MSI files, .msc file manipulation, and LOLBins for execution, targeting defense, financial services, government, utilities, and critical infrastructure in China, the United States, and Russia.

Goals & Targeting

The primary motivation is financial gain through data theft, ransomware deployment, or extortion. Water Gamayun selectively targets strategic sectors—defense, government, utilities, finance, and critical infrastructure—in jurisdictions that offer both economic value and opportunities to disrupt operations. The actor seeks high‑value, highly connected environments where compromised data can be leveraged for blackmail or leverage in broader geopolitical maneuvers.

Enhanced Description

Key Capabilities

  • Exploitation of MSC EvilTwin (CVE-2025-26633) to inject code into mmc.exe
  • Multi‑stage obfuscated PowerShell payloads
  • Password‑protected archives and decoy documents
  • Creation of directories mimicking legitimate system paths (e.g., C:\Windows System32)
  • Embedding Base64‑encoded payload strings in loader files
  • Persistence via SilentPrism backdoor
  • Persistence via DarkWisp backdoor
  • Deployment of malicious payloads through signed Microsoft Installer (.msi) files
  • Manipulation of Windows .msc files and use of MUIPath for execution control
  • Leveraging LOLBins for delivery and execution
  • Credential and data theft using EncryptHub Stealer variants, Stealc, Rhadamanthys

MITRE ATT&CK Tactics

Execution
Defense Evasion
Persistence
Privilege Escalation
Exfiltration
Initial Access
Credential Access
Discovery
Command and Control

ATT&CK Techniques

T1203
T1059.001
T1027
T1036
T1071
T1047
T1069.002
T1082
T1105
T1218.005
T1218.011
T1134
T1218.007
T1112

Software / Tooling

EncryptHub Stealer
SilentPrism
DarkWisp
Rhadamanthys
Stealc

Campaigns & Victims

Water Gamayun demonstrates a high-velocity, opportunistic operational tempo. It typically exploits zero‑day vulnerabilities for initial compromise, then layers obfuscation and persistence tools to maintain stealth. Victims are chosen from sectors with valuable data or critical services; the actor prefers environments where lateral movement can expand reach rapidly. Notable past operations include deployment against a US defense contractor using the MSC EvilTwin flaw and subsequent use of signed MSI files to deliver malicious shells. The actor’s campaigns have been observed to pivot quickly across domains, often changing C2 endpoints and leveraging legitimate protocols for exfiltration.

IOC Patterns

  • Use of .msc files for malicious execution
  • Creation of directories mimicking system paths with spaces
  • Embedded Base64‑encoded payload strings within loader files
  • Password‑protected archives used as decoys
  • Signed MSI file deployment
  • Exploitation of CVE-2025-26633 via mmc.exe

Recommended Actions

  • Apply timely patches for CVE-2025-26633 and related MMC vulnerabilities
  • Monitor .msc file execution for anomalous behavior
  • Deploy threat detection that flags hidden PowerShell activity and obfuscated payloads
  • Alert on creation of suspicious directories or names mimicking system paths
  • Validate legitimacy of signed MSI deployments from trusted sources
  • Implement application whitelisting to restrict LOLBin usage
  • Conduct regular hunting for SilentPrism and DarkWisp backdoors
  • Use sandbox analysis to review password‑protected archives

Suggested Tags

Water Gamayun
EncryptHub
LARVA-208
MSC EvilTwin
CVE-2025-26633
Zero-day exploitation
PowerShell obfuscation
Backdoor
Russian APT
ZDI-25-150
Signed MSI delivery
LOLBins
Custom backdoor
SilentPrism
DarkWisp

Confidence Assessment

The evidence provided confirms the use of MSC EvilTwin (CVE‑2025‑26633) and specific backdoors, indicating strong confidence in these capabilities. While attribution to a Russian origin is supported by multiple analysts, details such as first/last seen dates and full campaign chronology remain incomplete, creating uncertainty around operational scope and lifecycle. Information gaps persist regarding the exact extent of exfiltration methods and whether ransomware has been deployed in all observed incidents.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 3 Domain 14 MD5 Hash 3

References

  1. www.trendmicro.com — Cited by web research for: ZDI-25-150
  2. research.splunk.com — Cited by web research for: T1685
  3. research.splunk.com — Cited by web research for: T1574.001
  4. www.trendmicro.com — Cited by web research for: Scheduled Tasks
  5. www.zscaler.com — Cited by web research for: Payload

Intel Summary

45

Techniques

42

Tools

0

Campaigns

54

IOCs

0

Observed Data

11

Tactics

Tags

Zero-Day Exploitation
Backdoor / C2
Data Exfiltration
APT
espionage
cyber-espionage
zero-day exploits
Water Gamayun
EncryptHub
LARVA-208
MSC EvilTwin
CVE-2025-26633
Zero-day exploitation
PowerShell obfuscation
Backdoor
Russian APT
ZDI-25-150
Signed MSI delivery
LOLBins
Custom backdoor
SilentPrism
DarkWisp

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.