Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Russian group Encrypthub exploits vulnerability in MSC Eviltwin to deploy Fickle Stealer malware
Celebrities

Russian group Encrypthub exploits vulnerability in MSC Eviltwin to deploy Fickle Stealer malware

By August 16, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 16, 2025Ravi LakshmananMalware/Vulnerabilities

Encrypthub exploits vulnerability in MSC Eviltwin

A threat actor known as Encrypthub continues to provide malicious payloads by exploiting the currently maintained security flaws that affect Microsoft Windows.

TrustWave SpiderLabs said it had recently observed an enliptob campaign that links the exploitation of vulnerabilities in the Microsoft Management Console (MMC) framework (CVE-2025-26633, aka MSC Eviltwin) to a vulnerability to trigger infection routines via Rogue Microsoft Console (MSC) files.

“These activities are part of a wide range of continuing malicious activities that bypass social engineering and security defenses and fuse technological exploitation to control the internal environment,” said Trustwave researchers Nathaniel Morales and Nikita Kazymirskyi.

Encrypthub is a Russian hacking group that was also tracked as Larva-208 and Water Gamayun and first became prominent in mid-2024. The financially motivated crew operates at a high tempo and is known for infecting targets with steeler malware, utilizing several methods, including fake job offers, portfolio reviews and even ways to compromise steam games.

Cybersecurity

The abuse of threat actor CVE-2025-26633 was previously recorded by Trend Micro in March 2025, and discovered an attack that offered two backdoors called SilentPrism and DarkWisp.

The latest attack sequence includes threat actors who claim to be from the IT department and send requests to the target with the aim of Microsoft teams launching a remote connection and deploying a secondary payload using PowerShell commands.

Inside the dropped files there are two MSC files with the same name. One is benign and malicious. This is used to trigger CVE-2025-26633, and ultimately an incorrect MSC file will be executed when the harmless counterpart is launched.

For that part, the MSC file communicates with the encrypthub command and control (C2) server to collect system information from an external server, establish host persistence, and to receive and execute a malicious payload that includes theft, known as Fickle Stealer.

“The script receives AES encrypted commands from the attacker, decrypts them, and runs the payload directly on the infected machine,” the researchers said.

Also deployed by threat actors in the course of the attack is CVE-2025-26633, which abused Brave Support, a legitimate platform associated with Brave Web Browser, a ZIP archive containing two MSC files to weaponize GO-2025-26633.

What’s important is that uploading file attachments to the brave support platform is restricted to new users, indicating that attackers somehow get unauthorized access to accounts with upload permissions to separate the scheme.

Other tools deployed include a Golang backdoor that works in both client and server modes to send system metadata to the C2 server, and sets up the C2 infrastructure using the Socks5 Proxy Tunneling protocol.

There is also evidence that threat actors continue to rely on video conferencing lures. This time, we’ll set up a fake platform like Rivatalk and download the MSI installer to deceive the victim.

Running the installer will deliver some files. Legal Early Fire Prevention Anti-Malware (ELAM) installer binaries from Symantec are used to sideload malicious dlls.

Identity Security Risk Assessment

It is designed to collect system information and remove it into a C2 server, waiting for encrypted PowerShell instructions that are decoded and executed so that an attacker has full control over the system. The malware launches a background job that generates fake browser traffic by displaying fake “system configuration” pop-up messages as Ruses and creating HTTP requests on popular websites to blend C2 communications with normal network activity.

“The Enliptob threat actors represent highly resourced and adaptable enemies, combining social engineering, abuse of trustworthy platforms, and exploitation of vulnerabilities in systems to maintain sustainability and control,” Trustwave said.

“The use of fake video conferencing platforms, encrypted command structures, and evolving sets of malware tools highlights the importance of layered defense strategies, continuous threat intelligence and user cognitive training.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCrypto Company Gemini File for Winklevoss Twins IPO
Next Article What was the first human species?

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Trending Posts

BTS’s “Come Over” was chosen as this week’s best new song

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Cardi B, Fat Joe and other musicians react

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.