Russian Hackers Exploit CVE-2025-26633 via MSC EvilTwin to Deploy SilentPrism and DarkWisp

Two new backdoors, SilentPrism and DarkWisp, have been discovered to be delivered by the threat actors responsible for the zero-day exploitation of a newly patched security flaw in Microsoft Windows.

The behavior has been linked to Water Gamayun, a suspected Russian hacker collective also known as LARVA-208 and EncryptHub.

Using methods like the IntelliJ runnerw.exe for command execution, the threat actor mainly uses malicious provisioning packages, signed.msi files, and Windows MSC files to deploy payloads, according to a follow-up analysis released last week by Trend Micro researchers Aliakbar Zahravi and Ahmed Mohamed Ibrahim.

A vulnerability in the Microsoft Management Console (MMC) architecture known as CVE-2025-26633 (also known as MSC EvilTwin) has been actively exploited by Water Gamayun read more about Russian Hackers Exploit CVE-2025-26633 via MSC EvilTwin to Deploy SilentPrism and DarkWisp.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *