A Deep Dive into Water Gamayun’s Arsenal and Infrastructure


Water Gamayun, a suspected Russian threat actor also known as EncryptHub and Larva-208, has been exploiting the MSC EvilTwin (CVE-2025-26633), a zero-day vulnerability that was patched on March 11.

In the first installment of this two-part series, Trend Research discussed in depth its discovery of an Water Gamayun campaign exploiting this vulnerability. In this blog entry, we will cover the various delivery methods, custom payloads and techniques used by Water Gamayun to compromise victim systems and exfiltrate sensitive data.

Read more…
Source: Trend Micro


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Securing the overlooked corners of the Software Development Lifecycle (SDLC) supply chain

    August 21, 2026

    While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on. Unit 42 research shows this happening at ...

  • Zombie Card: An expired Visa credit card can be used for purchases

    August 21, 2026

    Did you know there is still a good reason to physically destroy your expired credit card? Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering. University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, ...

  • The invisible passenger in your car

    August 21, 2026

    While monitoring Android threats in June 2026, Kaspersky discovered a new piece of Android malware. What struck the researchers as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might ...

  • Hackers are spending millions on expired domains to enable malware scams

    August 21, 2026

    A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about. New research from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least ...

  • Medical records, SSNs, and bank details exposed in CareCloud data breach

    August 21, 2026

    Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year. The New Jersey-based company, which provides electronic health record (EHR) and practice management services, first flagged the intrusion in an SEC filing back in March, but the true scope ...

  • Identity abuse through trusted communication channels

    August 20, 2026

    Identity has become a primary security boundary for most organizations, reducing the ability to solely trust other boundaries once associated with corporate networks. Users authenticate to cloud services using enterprise identities that provide access to collaboration platforms, business applications and sensitive data. With the adoption of software-as-a-service (SaaS) on the rise, people are shifting to ...