Tag: Microsoft Management Console (MMC)

Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
News

Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware

The threat actor EncryptHub is still using a Microsoft Windows security hole that has been patched to spread harmful payloads. According to Trustwave SpiderLabs, it recently discovered an EncryptHub campaign that uses a rogue Microsoft Console (MSC) file to initiate the infection process, combining social engineering with the exploitation of a Microsoft Management Console (MMC) framework vulnerability (CVE-2025-26633, also known as MSC EvilTwin). According to Trustwave experts Nathaniel Morales and Nikita Kazymirskyi, these actions are a part of a large, continuous wave of hostile activity that combines technical exploitation and social engineering to get past security measures and take control of internal environments. The Russian hacker collective EncryptHub, also known as LARV...