Tag: SilentPrism

Russian Hackers Exploit CVE-2025-26633 via MSC EvilTwin to Deploy SilentPrism and DarkWisp
News

Russian Hackers Exploit CVE-2025-26633 via MSC EvilTwin to Deploy SilentPrism and DarkWisp

Two new backdoors, SilentPrism and DarkWisp, have been discovered to be delivered by the threat actors responsible for the zero-day exploitation of a newly patched security flaw in Microsoft Windows. The behavior has been linked to Water Gamayun, a suspected Russian hacker collective also known as LARVA-208 and EncryptHub. Using methods like the IntelliJ runnerw.exe for command execution, the threat actor mainly uses malicious provisioning packages, signed.msi files, and Windows MSC files to deploy payloads, according to a follow-up analysis released last week by Trend Micro researchers Aliakbar Zahravi and Ahmed Mohamed Ibrahim. A vulnerability in the Microsoft Management Console (MMC) architecture known as CVE-2025-26633 (also known as MSC EvilTwin) has been actively exploited ...