TF-MAL-ps1.silent_prism
📛 Threat Title
Malware family: SilentPrism
Description
ThreatFox malware family `ps1.silent_prism`. Printable name: SilentPrism.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.solosecurities.com
Water Gamayun's use of CVE-2025-26633, MSC EvilTwin, SilentPrism , and DarkWisp demonstrates a new level of cyber sophistication. This is not just another malware attack—it's an evolution in cyber warfare.
-
web:cybersecuritynews.com
A sophisticated campaign by Russian threat actors exploiting a critical zero-day vulnerability in the Microsoft Management Console (MMC).
-
web:ec2-3-226-136-182.compute-1.amazonaws.com
Russian hackers exploit CVE-2025-26633 using MSC EvilTwin to deploy SilentPrism and DarkWisp, enhancing their cyberattack capabilities.
-
web:news.backbox.org
The threat actors behind the zero-day exploitation of a recently-patched security vulnerability in Microsoft Windows have been found to deliver two new backdoors called SilentPrism and DarkWisp. The activity has been attributed to a suspected Russian hacking group called Water Gamayun, which is also known as EncryptHub and LARVA-208.
-
web:sensorstechforum.com
Payloads are dropped and executed silently Payloads Delivered via CVE-2025-26633 Trend Micro researchers observed that Water Gamayun used the MSC EvilTwin technique to deliver a variety of malware strains: EncryptHub Stealer This modular info-stealer captures browser credentials, system metadata, clipboard content, and cryptocurrency wallet data.
-
web:thehackernews.com
Water Gamayun exploited CVE-2025-26633 to deploy SilentPrism , DarkWisp, and stealers with persistence.
-
web:windowsforum.com
Hackers Exploit Windows MMC Zero-Day to Execute Malicious Code A new cybersecurity scare is unsettling the Windows community. A recently uncovered zero-day vulnerability in the Microsoft Management Console (MMC) — tracked as CVE-2025-26633 — is being actively exploited by a sophisticated campaign attributed to Russian threat actors. Known by aliases such as Water Gamayun, EncryptHub, and ...
-
web:www.secpod.com
Exploitation: When opened, the crafted file abuses input sanitization flaws in MMC, bypassing security warnings and launching malware . Payload Execution: Stealthy installer drops payloads such as SilentPrism or DarkWisp, which run with administrative privileges.
-
web:www.securityexplore.com
One such malware is a PowerShell implant dubbed SilentPrism that can set up persistence, execute multiple shell commands simultaneously, and maintain remote control, while also incorporating anti-analysis techniques to evade detection.
-
web:www.technewscentre.com
The malware is also capable of executing cleanup operations to remove forensic traces. MSC EvilTwin Loader and Rhadamanthys Stealer In addition to SilentPrism and DarkWisp, the hackers use an MSC EvilTwin loader, weaponizing CVE-2025-26633 to execute a malicious .msc file.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.