PULSE NAME
A Deep Dive into Water Arsenal and Infrastructure
WHITE Water Gamayun AlienVault 2025-03-29 Modified: 2025-04-28
245
IOCs
HIGH VOLUME
Water Gamayun, a suspected Russian threat actor, exploits the MSC EvilTwin zero-day vulnerability (CVE-2025-26633) to compromise systems and exfiltrate data. The group uses custom payloads like EncryptHub Stealer variants, SilentPrism and DarkWisp backdoors, as well as known malware like Stealc and Rhadamanthys. Their delivery methods include malicious provisioning packages, signed .msi files, and Windows MSC files. The attackers employ techniques such as LOLBins and encrypted communications to evade detection. Their infrastructure includes C&C servers for managing infected systems and exfiltrating data. The campaign highlights the group's adaptability and sophistication in cyber espionage operations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
EncryptHub Stealer SilentPrism DarkWisp Stealc Rhadamanthys
Indicators of Compromise (62 / 245 total)
All domain FileHash-MD5 FileHash-SHA1 FileHash-SHA256 hostname CVE URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 005277fccc94e59bcc80b2c0908e7651 2025-03-29
FileHash-MD5 011827ebdf113755102a47987b718587 2025-03-29
FileHash-MD5 06b419c9fd1fd280d35f2b9b8ac40a75 2025-03-29
FileHash-MD5 075656972704100d4958d49ac14e5a6b 2025-03-29
FileHash-MD5 09bb4f4aa903cad0453eccfce222baa0 2025-03-29
FileHash-MD5 0f66f6f6d5b6e7ed79716d0fee4f3d8f 2025-03-29
FileHash-MD5 1ecdb781351a45d0a77f0db0b1268157 2025-03-29
FileHash-MD5 210de49b640b9d06985f882404dc49fa 2025-03-29
FileHash-MD5 239e8a3ee1fafe452d0b59eadb32247b 2025-03-29
FileHash-MD5 251acf4b0b4ee6f94cc5492b9f42b977 2025-03-29
FileHash-MD5 28820ba7d33905a4e6593bd84a78db71 2025-03-29
FileHash-MD5 34623eddb440906776585b6d4f45ea32 2025-03-29
FileHash-MD5 34ac8cb05f744ed79f166dfdd357c11a 2025-03-29
FileHash-MD5 3c4bb1da1a85e000a3abc4ef49771b19 2025-03-29
FileHash-MD5 4099cff2929d423a1b2816cbbecab52f 2025-03-29
FileHash-MD5 46eae0ac01ddb2b25e366045a166f84a 2025-03-29
FileHash-MD5 46f9e14a5113b24bd3374ab586287dca 2025-03-29
FileHash-MD5 48ce28da8e254894d50deeb9850ad945 2025-03-29
FileHash-MD5 4bf2348470bee88cd06bd9e3b7bd29de 2025-03-29
FileHash-MD5 4fef7578494c3f065010b234da9e6d23 2025-03-29
FileHash-MD5 50f4a9ba7bd5fba9b3a90f702efa2e26 2025-03-29
FileHash-MD5 5488c867b16fa0ff44dc975caf8e5f8e 2025-03-29
FileHash-MD5 59fc531c4c9545c0d888b47ec924745b 2025-03-29
FileHash-MD5 5b08d4783206d759d3734d480f551453 2025-03-29
FileHash-MD5 5cb5a33ea3d47dec26ee87778fed08c4 2025-03-29
FileHash-MD5 5fa215f4d87e9295682ed0551de59d9c 2025-03-29
FileHash-MD5 636409a3df18106967974294f7b14491 2025-03-29
FileHash-MD5 660698dbe0a658de9cbe74f86f3ad1f0 2025-03-29
FileHash-MD5 6a87c4c402bab2e045f36ef81f0088ab 2025-03-29
FileHash-MD5 6e90358d70a4a4c6d49dab693267a381 2025-03-29
FileHash-MD5 7b1dba1ade3eb44e52fb70f5fbc68e98 2025-03-29
FileHash-MD5 8286ba73cdeaa326a9fb956a90e77296 2025-03-29
FileHash-MD5 87792cf4bd370f483a293a23c4247c50 2025-03-29
FileHash-MD5 894d8b4a721fd1931318e475f7872b9c 2025-03-29
FileHash-MD5 97262b9ab8ad8845620910772285fde9 2025-03-29
FileHash-MD5 975a71447393629b33ccce36b6b9f085 2025-03-29
FileHash-MD5 9a7d80b9f8afc7ec88c1e92b143a263b 2025-03-29
FileHash-MD5 9ceb42d9bbf4715398248597945db1f4 2025-03-29
FileHash-MD5 9f17d0e2a2e20f8141bf55d374c358b2 2025-03-29
FileHash-MD5 a94d7d111993bfcc4bbc3fbe197a9edb 2025-03-29
FileHash-MD5 abaa46bc704842d6cc6f494c21546ae6 2025-03-29
FileHash-MD5 adffd4d8ba3af7ea2bf6ca7a89a6c79a 2025-03-29
FileHash-MD5 ae52064717272ae5059f57799894f85a 2025-03-29
FileHash-MD5 b000fb1bcf8f900bb94efa5b9918f9e8 2025-03-29
FileHash-MD5 b3e03ff421249ce0a77d6c7ef2bc2f3f 2025-03-29
FileHash-MD5 b8b0f489bde2a0960d4669273c20c7ef 2025-03-29
FileHash-MD5 ba3fc03734e30d87fe4dfe96ac3ea03c 2025-03-29
FileHash-MD5 bed44e526837e0501144a3c735b9080b 2025-03-29
FileHash-MD5 c20424c77a0d9a9846506bb20219bec8 2025-03-29
FileHash-MD5 c727669134ac63e962d223517c3c567c 2025-03-29
FileHash-MD5 dfa164f1695a9bd6c212e61c9526b668 2025-03-29
FileHash-MD5 e2d005af8f840f371ab2cef870dacbcf 2025-03-29
FileHash-MD5 e59a025f9310d266190b91f5330fde8d 2025-03-29
FileHash-MD5 e986b499c7b504a93a809d33f9e72bc8 2025-03-29
FileHash-MD5 fab909bfcaf94b8a628b5a991eae2896 2025-03-29
FileHash-MD5 1c34b88280d660051b69ccb40660e71f 2025-03-29
FileHash-MD5 1fbe357c26133a4b39b96fdd2c48f1ae 2025-03-29
FileHash-MD5 2f8bf3e5b6cbdb0c8e5935b078711867 2025-03-29
FileHash-MD5 3371da6397159dbced2794c12aeb80c6 2025-03-29
FileHash-MD5 42b55615cbaa014f246097bd904d7ff2 2025-03-29
FileHash-MD5 99a80820ae6dc60c9e9307e6ed8ef211 2025-03-29
FileHash-MD5 f0df469c3459a6a3b98b7b69b07bf61b 2025-03-29