Windows cyber attack hero image showing Water Gamayun APT using MSC EvilTwin CVE-2025-26633 with code skull warning icon padlock and malicious RAR to PDF lure

Water Gamayun Exploits New MSC EvilTwin Threat

Category: Cybersecurity
Tags:

Water Gamayun increased its activity after a new MSC EvilTwin vulnerability (CVE-2025-26633) surfaced in Windows systems. The group uses a layered attack chain that blends trusted binaries, deep obfuscation, and convincing decoy files to slip past security controls. Victims are redirected from compromised sites to malicious lookalike domains that deliver weaponized archives disguised as PDFs. Once triggered, the payload abuses MMC TaskPad functionality and encoded PowerShell to expand access and establish persistence.

Relevant Source (Zscaler): Zscaler Threat Hunting Discovers and Reconstructs a Sophisticated Water Gamayun APT Group Attack
Zscaler’s research details a multi-stage Water Gamayun campaign that abuses the MSC EvilTwin vulnerability (CVE-2025-26633), using compromised sites, lookalike domains, RAR-as-PDF lures, MMC TaskPad abuse, and encoded PowerShell to gain persistence on Windows systems.

Quick Facts

  • Targets enterprise and government networks
  • Uses CVE-2025-26633 MSC EvilTwin flaw in Windows
  • Attack begins with redirects to fake job download pages
  • Malicious RAR archive drops a crafted .msc file
  • PowerShell payload downloads tools and launches hidden executables
  • Loader maintains long-term access and covert network beacons

Attack Technique Basics

Water Gamayun deploys a multi-stage payload chain designed to hide malicious behavior behind legitimate Windows components. The attack starts with a compromised website that silently redirects users to a clone domain serving a “PDF” packed inside a RAR archive. Once opened, the file writes a crafted .msc configuration that mmc.exe loads as part of its normal behavior.

  • Abuse of TaskPad snap-ins to run encoded PowerShell
  • Password-protected archives to conceal second-stage content
  • Decoy documents to lower suspicion

This design helps the threat actors slip past automated detection since early steps look like routine user actions. The structure also limits visible artifacts until later stages execute, giving attackers room to expand their footprint.

Relevant Source (Microsoft): Malvertising campaign leads to info stealers hosted on GitHub
Microsoft Threat Intelligence describes a multi-stage web-based campaign that uses redirects, malicious downloads, and staged payload delivery, providing a strong parallel to the redirect and decoy-driven technique outlined here.

Why This Threat Matters

The campaign shows how attackers can turn niche Windows features into reliable execution paths. The EvilTwin flaw gives the group an opening through mmc.exe, a trusted binary rarely flagged as suspicious. This makes the first-stage execution difficult for security teams to pick up through traditional endpoint rules.

  • Bypasses security monitoring based on common file types
  • Injects code through legitimate system processes
  • Uses obfuscation and window-hiding modules
  • Delivers staged components for persistence
  • Communicates with external servers through concealed beacons

The mix of social engineering and technical depth raises the risk for organizations that rely on standard antivirus or signature-based detection. A layered strategy allows the attackers to stay embedded while extracting data or preparing follow-up intrusions.

Relevant Source (CISA): PRC State-Sponsored Actors Compromise and Maintain Access to U.S. Critical Infrastructure
CISA outlines how Volt Typhoon uses living-off-the-land techniques and legitimate Windows processes for stealthy persistence, reinforcing the broader risk of trusted binaries being abused to bypass monitoring.

Immediate Protective Steps

Defenders can reduce exposure to this threat by tightening monitoring around rare execution paths and encoded PowerShell activity. The attack chain relies on small but detectable anomalies when viewed together.

  1. Watch for .msc file creation outside administrative tasks
  2. Flag encoded PowerShell activity launched by mmc.exe
  3. Monitor for unusual redirects leading to lookalike domains
  4. Inspect password-protected archives arriving through web searches
  5. Track unknown executables communicating with external Ips

A careful review of endpoint logs and web filtering rules helps disrupt the early stages before payloads begin downloading additional modules. Strengthening user awareness around disguised attachments also reduces the attack’s initial success rate.

Relevant Source (CISA): Keeping PowerShell: Measures to Use and Embrace
Guidance from CISA on logging, monitoring, and configuring PowerShell securely so defenders can detect and prevent malicious encoded command abuse.

Relevant Source (Microsoft): Lumma Stealer: Breaking down the delivery techniques and capabilities of a prolific infostealer
Microsoft outlines detection signals for suspicious PowerShell use, hidden processes, and malicious downloads that align with the monitoring and logging steps described here.

The Big Picture

Advanced persistent threats are evolving toward deeper abuse of built-in system components. Water Gamayun’s workflow demonstrates how attackers move away from obvious exploits and toward subtle chains that blend into normal administrative operations. This approach narrows the window for detection and lets malicious scripts operate under the cover of trusted binaries.

The reliance on staged payloads also signals a shift toward long-term access. Each step builds on the last, giving attackers multiple fallback points if any portion of the chain is interrupted. Security teams need visibility across the entire process, not only the final malware drop, to stop campaigns with this level of layering.

Conclusion

CVE-2025-26633 opened a fresh avenue for Water Gamayun to push complex, stealthy malware into enterprise environments. Careful payload layering and the misuse of MMC snap-ins make the threat harder to spot, but not impossible. Strong monitoring, strict filtering, and user awareness give organizations the edge they need to stop this attack chain before it takes hold.

FAQ

What is the MSC EvilTwin vulnerability?
A Windows flaw (CVE-2025-26633) that lets crafted .msc files trigger unintended execution through mmc.exe.

How does the attack begin?
Victims land on a compromised site and get redirected to a clone domain serving a malicious RAR file disguised as a PDF.

Why is mmc.exe used?
MMC is a trusted Windows binary, so attackers abuse it to run encoded PowerShell without raising early alarms.

What payloads are involved?
The chain uses UnRAR.exe, password-protected archives, PowerShell scripts, and a final loader named ItunesC.exe.

How can organizations detect this threat?
Look for unusual .msc files, encoded PowerShell activity, suspicious process chains, and outbound traffic to unknown servers.

Hacker silhouette sitting at multiple monitors showing code and system activity

How JENI Strengthens System Defense

Organizations face rising pressure to maintain visibility across Windows components that attackers often abuse. JENI supports this effort by tightening system hygiene, improving performance, and reducing the blind spots that allow threats to operate in the background. A cleaner environment makes malicious activity easier to detect and harder for APT groups to hide behind routine processes.

Key Ways JENI Helps:

  • Improves system stability so unexpected process chains stand out
  • Cleans residual clutter that attackers often use to mask payloads
  • Highlights abnormal resource spikes linked to hidden scripts

JENI brings structure to systems that handle sensitive workloads and need predictable performance. The platform helps reduce noise from unnecessary files, unstable services, and outdated components, which often create the gaps attackers rely on. Strong system hygiene supports faster investigation when something unusual appears in logs or execution flow. Consistent optimization gives teams a clearer baseline, making it easier to spot activity similar to Water Gamayun’s multi-stage tactics.

Published on November 26, 2025 at 3:49 PM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.