As cited
Copy frozen at (site build).
threat intel
Zscaler Threat Hunting Discovers and Reconstructs a Sophisticated Water Gamayun APT Group Attack
Zscaler Threat Hunting reconstructed a multi-stage attack campaign attributed to Water Gamayun, a Russia-aligned APT group, that exploited CVE-2025-26633 (MSC EvilTwin), a Windows MMC vulnerability, to deliver malware loaders. The attack chain began with a compromised BELAY Solutions website redirecting victims to a lookalike domain hosting a double-extension RAR file masquerading as a PDF, which when opened, injected code into mmc.exe via TaskPad commands to execute hidden, obfuscated PowerShell stages. Attribution was supported by rare exploitation of the CVE, distinctive obfuscation patterns, process-hiding tradecraft, dual-path command and control infrastructure, and employment-themed social engineering consistent with the group's known operations.
Why it matters: Enterprises and government networks are at risk from Water Gamayun's use of CVE-2025-26633 for initial compromise and supply-chain attack vectors; security teams should monitor for double-extension file downloads, suspicious redirects from legitimate domains, and MMC-based code injection patterns to detect this active threat.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Zscaler Threat Hunting Discovers and Reconstructs a Sophisticated Water Gamayun APT Group Attack
Zscaler Threat Hunting reconstructed a multi-stage attack campaign attributed to Water Gamayun, a Russia-aligned APT group, that exploited CVE-2025-26633 (MSC EvilTwin), a Windows MMC vulnerability, to deliver malware loaders. The attack chain began with a compromised BELAY Solutions website redirecting victims to a lookalike domain hosting a double-extension RAR file masquerading as a PDF, which when opened, injected code into mmc.exe via TaskPad commands to execute hidden, obfuscated PowerShell stages. Attribution was supported by rare exploitation of the CVE, distinctive obfuscation patterns, process-hiding tradecraft, dual-path command and control infrastructure, and employment-themed social engineering consistent with the group's known operations.
Why it matters: Enterprises and government networks are at risk from Water Gamayun's use of CVE-2025-26633 for initial compromise and supply-chain attack vectors; security teams should monitor for double-extension file downloads, suspicious redirects from legitimate domains, and MMC-based code injection patterns to detect this active threat.
- Source published
- First seen by Cybersecurity Tracker