κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
άμυνα
.

Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware

16/08/2025

Aug 16, 2025Ravie LakshmananMalware / Vulnerability
The threat actor known as EncryptHub is continuing to exploit a now-patched security flaw impacting Microsoft Windows to deliver malicious payloads.
Trustwave SpiderLabs said it recently observed an EncryptHub campaign that brings together social engineering and the exploitation of a vulnerability in the Microsoft Management Console (MMC) framework (CVE-2025-26633, aka MSC EvilTwin) to trigger the infection routine via a rogue Microsoft Console (MSC) file.
“These activities are part of a broad, ongoing wave of malicious activity that blends social engineering with technical exploitation to bypass security defenses and gain control over internal environments,” Trustwave researchers Nathaniel Morales and Nikita Kazymirskyi said.
EncryptHub, also tracked as LARVA-208 and Water Gamayun, is a Russian hacking group that first gained prominence in mid-2024. Operating at a high tempo, the financially motivated crew is known for leveraging several methods, including fake job offers, portfolio review, and even compromising Steam games, to infect targets with stealer malware.

The threat actor’s abuse of CVE-2025-26633 was previously documented by Trend Micro in March 2025, uncovering attacks that deliver two backdoors called SilentPrism and DarkWisp.
The latest attack sequence involves the threat actor claiming to be from the IT department and sending a Microsoft Teams request to the target with the goal of initiating a remote connection and deploying secondary payloads by means of PowerShell commands.
Among the files dropped are two MSC files with the same name, one benign and the other malicious, that’s used to trigger CVE-2025-26633, ultimately resulting in the execution of the rogue MSC file when its innocuous counterpart is launched.

The MSC file, for its part, fetches and executes from an external server another PowerShell script that collects system information, establishes persistence on the host, and communicates with an EncryptHub command-and-control (C2) server to receive and run malicious payloads, including a stealer called Fickle Stealer.

“The script receives AES-encrypted commands from the attacker, decrypts them, and runs the payloads directly on the infected machine,” the researchers said.
Also deployed by the threat actor over the course of the attack is a Go-based loader codenamed SilentCrystal, which abuses Brave Support, a legitimate platform associated with the Brave web browser, to host next-stage malware – a ZIP archive containing the two MSC files to weaponize CVE-2025-26633.
What makes this significant is that uploading file attachments on the Brave Support platform is restricted for new users, indicating that the attackers somehow managed to obtain unauthorized access to an account with upload permissions to pull off the scheme.

Some of the other tools deployed include a Golang backdoor that operates in both client and server mode to send system metadata to the C2 server, as well as set up C2 infrastructure by making use of the SOCKS5 proxy tunneling protocol.
There is also evidence that the threat actors are continuing to rely on videoconferencing lures, this time setting up phony platforms like RivaTalk to deceive victims into downloading an MSI installer.
Running the installer leads to the delivery of several files: the legitimate Early Launch Anti-Malware (ELAM) installer binary from Symantec that’s used to sideload a malicious DLL that, in turn, launches a PowerShell command to download and run another PowerShell script.

It’s engineered to gather system information and exfiltrate it to the C2 server, and await encrypted PowerShell instructions that are decoded and executed to give attackers full control of the system. The malware also displays a fake “System Configuration” pop-up message as a ruse, while launching a background job to generate fake browser traffic by making HTTP requests to popular websites so as to blend C2 communications with normal network activity.
“The EncryptHub threat actor represents a well-resourced and adaptive adversary, combining social engineering, abuse of trusted platforms, and the exploitation of system vulnerabilities to maintain persistence and control,” Trustwave said.
“Their use of fake video conferencing platforms, encrypted command structures, and evolving malware toolsets underscores the importance of layered defense strategies, ongoing threat intelligence, and user awareness training.”

Source: thehackernews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-2

3 Windows File Explorer add-ons that fix Microsoft's biggest pain points

File Explorer is one of the oldest parts of Windows, and you can tell. Microsoft has added tabs and refreshed the icons, but the core experience still needs work. For example, the layout looks rigid, and everyday actions like batch renaming need third-party help to be more complete. File Explorer also feels flat to look at, with almost no way to change its appearance. Small pain points like these … [Read More...]

The single Docker container that made me a home lab power user

For years, I treated my home lab like a necessary chore – a collection of services running on command line interfaces that required constant SSH logins just to check logs or reboot a container. I knew the power of Docker, but managing multiple environments across different hardware was often a confusing, time-consuming mess. Source: xda-developers.com … [Read More...]

Intel N150 mini PC: The ultimate starter home lab device

If you've started on your home lab journey by heavily reading subreddits and networking forums, you probably have a vision of ex-enterprise hardware in a rack that stretches from floor to ceiling. Which is cool, and gives the desired visual effect, but it's not the only way to do things. And for those starting out, it might not even be the best way, as the hidden costs of self-hosting mount up … [Read More...]

Newsom signs bill giving Uber and Lyft drivers in California the right to unionize

Drivers for ride-hailing apps like Uber and Lyft will soon have the right to unionize in California as independent contractors, thanks to a bill signed Friday by Governor Gavin Newsom. This is part of a larger deal between lawmakers, unions, and ride-hailing companies, resulting in the passage of separate bills supporting lower insurance requirements for Uber and Lyft, along with union rights for … [Read More...]

Stop trusting your ISP's router blindly

Of all the exciting things about getting a new internet connection, the router is probably the least thrilling. It's the beige box of networking, the unglamorous gatekeeper to the digital world. Your Internet Service Provider (ISP) is aware of this. They make setup and maintenance incredibly simple. Most providers offer or bundle a router with your new connection. If you agree, a technician shows … [Read More...]

Chromebooks are better than cheap Windows laptops

There are a few things in tech more depressing than a cheap Windows laptop. Between sluggish performance, application timeouts, dim displays, and poor battery life, you sacrifice a great deal to buy a sub-$600 Windows machine. Source: xda-developers.com … [Read More...]

If you’re not an AI startup, good luck raising money from VCs

New PitchBook data illustrates how dramatically AI is dominating startup investment, with 2025 on-track to become the first year when AI accounts for more than half of all VC money invested. PitchBook reports that VCs have poured $192.7 billion into the industry so far this year, out of a total $366.8 billion, according to Bloomberg. In the most recent quarter, AI accounted for 62.7% of the money … [Read More...]

7 unusual Linux distros built for one purpose (and why you should try them)

I often talk about switching to Linux as an alternative to Windows 11, something I've done myself on many of my machines. But while it's common to put Linux on the same playing field as Windows, it bears repeating that Linux itself isn't an operating system, and as a kernel, it's an extremely versatile piece of software that can be used for a lot of things. Source: xda-developers.com … [Read More...]

This self-hosted dashboard is the perfect hub for your family’s daily needs

If your family is anything like mine, you probably have sticky notes stuck all over your fridge, a WhatsApp chat dedicated to shopping lists, and chores that are barely tracked. It's a mess, and it only gets worse as more people are added to the mix. I've tried integrating apps and shared to-do lists, but they never stuck. The apps were, largely, too complicated for what should be everyday needs … [Read More...]

OpenAI acquires an AI-powered personal investing app

Just a day after dethroning SpaceX as the most valuable private company in the world, OpenAI has acquired another startup. This time, the AI giant acquired Roi, an app that offers a one-stop shop for all your financial portfolios and an AI chatbot that provides personalized investing advice. Details of the acquisition weren't made public, but TechCrunch reported that Sujith Vishwajith, the … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • 3 Windows File Explorer add-ons that fix Microsoft's biggest pain points
  • The single Docker container that made me a home lab power user
  • Intel N150 mini PC: The ultimate starter home lab device
  • Newsom signs bill giving Uber and Lyft drivers in California the right to unionize
  • Stop trusting your ISP's router blindly

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023