216.73.217.22

Water APT Multi-Stage Attack Uncovered

· Published 26/11/2025 00:43 · Modified 21/12/2025 18:01

Export JSON

Essential information

Published
26/11/2025 00:43
Modified
21/12/2025 18:01
Tags
2025-11-26 CVE-2025-26633 apt darkwisp encrypthub msc eviltwin obfuscation powershell rhadamanthys russia-aligned silentprism supply-chain zero-day
Related entities
1 vulnerabilities (cve), 4 observables, 1 intrusion sets (apt), 4 malware, 4 others

Description

A sophisticated multi-stage attack attributed to the Water Gamayun group has been analyzed. The attack begins with a compromised legitimate website redirecting to a lookalike domain, delivering a double-extension RAR payload disguised as a PDF. This payload exploits the vulnerability () to inject code into mmc.exe, initiating a series of hidden stages. The attack employs layered , password-protected archives, and process-hiding techniques to evade detection. The campaign's attribution to Water Gamayun is based on their unique exploitation methods, signature patterns, infrastructure design, and specific social engineering themes. The group's objectives include strategic intelligence gathering, credential theft, and long-term persistence through custom backdoors and information stealers.

External references