s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.silent_prism

📛 Threat Title

Malware family: SilentPrism

Category: SilentPrism First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.silent_prism`. Printable name: SilentPrism.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:blog.solosecurities.com

    Water Gamayun's use of CVE-2025-26633, MSC EvilTwin, SilentPrism , and DarkWisp demonstrates a new level of cyber sophistication. This is not just another malware attack—it's an evolution in cyber warfare.

  • web:cybersecuritynews.com

    A sophisticated campaign by Russian threat actors exploiting a critical zero-day vulnerability in the Microsoft Management Console (MMC).

  • web:ec2-3-226-136-182.compute-1.amazonaws.com

    Russian hackers exploit CVE-2025-26633 using MSC EvilTwin to deploy SilentPrism and DarkWisp, enhancing their cyberattack capabilities.

  • web:news.backbox.org

    The threat actors behind the zero-day exploitation of a recently-patched security vulnerability in Microsoft Windows have been found to deliver two new backdoors called SilentPrism and DarkWisp. The activity has been attributed to a suspected Russian hacking group called Water Gamayun, which is also known as EncryptHub and LARVA-208.

  • web:sensorstechforum.com

    Payloads are dropped and executed silently Payloads Delivered via CVE-2025-26633 Trend Micro researchers observed that Water Gamayun used the MSC EvilTwin technique to deliver a variety of malware strains: EncryptHub Stealer This modular info-stealer captures browser credentials, system metadata, clipboard content, and cryptocurrency wallet data.

  • web:thehackernews.com

    Water Gamayun exploited CVE-2025-26633 to deploy SilentPrism , DarkWisp, and stealers with persistence.

  • web:windowsforum.com

    Hackers Exploit Windows MMC Zero-Day to Execute Malicious Code A new cybersecurity scare is unsettling the Windows community. A recently uncovered zero-day vulnerability in the Microsoft Management Console (MMC) — tracked as CVE-2025-26633 — is being actively exploited by a sophisticated campaign attributed to Russian threat actors. Known by aliases such as Water Gamayun, EncryptHub, and ...

  • web:www.secpod.com

    Exploitation: When opened, the crafted file abuses input sanitization flaws in MMC, bypassing security warnings and launching malware . Payload Execution: Stealthy installer drops payloads such as SilentPrism or DarkWisp, which run with administrative privileges.

  • web:www.securityexplore.com

    One such malware is a PowerShell implant dubbed SilentPrism that can set up persistence, execute multiple shell commands simultaneously, and maintain remote control, while also incorporating anti-analysis techniques to evade detection.

  • web:www.technewscentre.com

    The malware is also capable of executing cleanup operations to remove forensic traces. MSC EvilTwin Loader and Rhadamanthys Stealer In addition to SilentPrism and DarkWisp, the hackers use an MSC EvilTwin loader, weaponizing CVE-2025-26633 to execute a malicious .msc file.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.