HomeSecurityRussian hackers develop SilentPrism and DarkWisp backdoors

Russian hackers develop SilentPrism and DarkWisp backdoors

Malicious actors who exploited a recently patched vulnerability in Microsoft Windows have been spotted distributing two new backdoors, named SilentPrism and DarkWisp.

See also: FamousSparrow hackers distribute SparrowDoor & ShadowPad backdoors

SilentPrism DarkWisp backdoor

This activity has been attributed to a suspected Russian hacker group called Water Gamayun, also known as EncryptHub and LARVA-208.

Water Gamayun has been linked to the active exploitation of the CVE-2025-26633 (also known as MSC EvilTwin), which is located within the Microsoft Management Console (MMC), in order to execute malware via a malicious Microsoft Console (.msc) file.

The attack chains include the use of provisioning packages (.ppkg), signed Microsoft Windows installer files (.msi) , and .msc files to deliver infostealer and backdoors (SilentPrism and DarkWisp) capable of persistent presence and data theft.

EncryptHub gained attention in late June 2024 after it used a GitHub repository named “encrypthub” to distribute various malware families, including infostealers, miners, and ransomware, via a fake WinRAR. The threat actors have since moved to their own infrastructure for command and control (C&C) purposes.

The .msi installers used in the attacks pretend to be legitimate messaging and meeting software, such as DingTalk, QQTalk , and VooV Meeting. They are designed to run a PowerShell downloader, which is then used to retrieve and execute the next stage of the payload on a compromised computer.

See also: Betruger: RansomHub ransomware group uses new backdoor

One of these malware is a PowerShell implant called SilentPrism, which can establish a persistent presence, execute multiple shell commands simultaneously, and maintain remote control, while incorporating anti-analysis techniques to evade detection. Another notable PowerShell backdoor is DarkWisp, which allows system identification, sensitive data extraction, and persistent presence.

Russian hackers develop SilentPrism and DarkWisp backdoors
Russian hackers develop SilentPrism and DarkWisp backdoors

The third payload used in the attacks is the MSC EvilTwin, which exploits the CVE-2025-26633 vulnerability to execute a malicious .msc file, ultimately leading to the deployment of the Rhadamanthys Stealer. The loader is also designed to perform system cleanup to avoid creating evidence.

Rhadamanthys is not the only infostealer in Water Gamayun's arsenal, as it has been observed delivering another one called StealC, as well as three custom PowerShell variants referred to as EncryptHub Stealer variant A, variant B , and variant C.

Further analysis of the malicious actor’s C&C infrastructure (“82.115.223[.]182”) revealed the use of PowerShell to download and execute the AnyDesk remote access software, as well as the ability for operators to send remote Base64-encoded commands to the victim’s machine.

See also: Lotus Panda targets governments with Sagerunex backdoor

Backdoors ,refer to special access mechanisms in a computer system or program that allow a user (usually an attacker or programmer) to bypass normal security measures and gain access without the authorization of legitimate users. The use of backdoors in computer systems can have serious security implications, which is why their detection and elimination is critical to protecting systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS