s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.dark_wisp

📛 Threat Title

Malware family: DarkWisp

Category: DarkWisp First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.dark_wisp`. Printable name: DarkWisp.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:blog.solosecurities.com

    Water Gamayun's use of CVE-2025-26633, MSC EvilTwin, SilentPrism, and DarkWisp demonstrates a new level of cyber sophistication. This is not just another malware attack—it's an evolution in cyber warfare.

  • web:ec2-3-226-136-182.compute-1.amazonaws.com

    Remote Access: DarkWisp allows attackers to maintain control over the compromised system, enabling further exploitation or lateral movement within networks. Stealth Operations: Both backdoors are designed to operate under the radar, making detection and remediation challenging for security teams.

  • web:hivepro.com

    Water Gamayun uses this vulnerability to deploy various malware strains, including data stealers like Rhadamanthys and Stealc, backdoors like DarkWisp and SilentPrism, and other malicious tools such as EncryptHub stealer.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Trend Micro, DarkWisp is a PowerShell-based backdoor and reconnaissance utility designed for unauthorized system access and intelligence gathering. It enables attackers to exfiltrate sensitive data while maintaining persistent control over the compromised system. The malware collects extensive information about the compromised system to create a detailed profile. It determines ...

  • web:news.backbox.org

    The threat actors behind the zero-day exploitation of a recently-patched security vulnerability in Microsoft Windows have been found to deliver two new backdoors called SilentPrism and DarkWisp . The activity has been attributed to a suspected Russian hacking group called Water Gamayun, which is also known as EncryptHub and LARVA-208.

  • web:thehackernews.com

    Water Gamayun exploited CVE-2025-26633 to deploy SilentPrism, DarkWisp , and stealers with persistence.

  • web:windowsforum.com

    Hackers Exploit Windows MMC Zero-Day to Execute Malicious Code A new cybersecurity scare is unsettling the Windows community. A recently uncovered zero-day vulnerability in the Microsoft Management Console (MMC) — tracked as CVE-2025-26633 — is being actively exploited by a sophisticated campaign attributed to Russian threat actors. Known by aliases such as Water Gamayun, EncryptHub, and ...

  • web:www.enigmasoftware.com

    Water Gamayun has been actively exploiting CVE-2025-26633 (aka MSC EvilTwin), a vulnerability in the Microsoft Management Console (MMC) framework, to execute malware using rogue Microsoft Console (.msc) files. New Backdoors: SilentPrism and DarkWisp The cybercriminals behind this zero-day attack have deployed two sophisticated backdoors—SilentPrism and DarkWisp . These tools facilitate ...

  • web:www.securityexplore.com

    Another PowerShell backdoor of note is DarkWisp , which enables system reconnaissance, exfiltration of sensitive data, and persistence. "Once the malware exfiltrates reconnaissance and system information to the C&C server, it enters a continuous loop waiting for commands," the researchers said.

  • web:www.technewscentre.com

    The malware is also capable of executing cleanup operations to remove forensic traces. MSC EvilTwin Loader and Rhadamanthys Stealer In addition to SilentPrism and DarkWisp , the hackers use an MSC EvilTwin loader, weaponizing CVE-2025-26633 to execute a malicious .msc file.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.