Загрузка...

🚨 Windows Zero-Day Exploit (CVE-2025-26633) | EncryptHub Hack Explained ⚠️

A Russian hacking group known as EncryptHub is exploiting a dangerous Windows zero-day vulnerability — tracked as CVE-2025-26633 (MSC EvilTwin) — to deploy stealer malware and exfiltrate sensitive data.

⚡ How the attack works:

Hackers pose as IT staff on Microsoft Teams 📞

Trick users into running a PowerShell loader (runner.ps1)

Drop two .msc files (one clean, one malicious)

Opening the clean file executes the malicious one 🖥️

This triggers build.ps1, which:
🔹 Collects system details
🔹 Maintains persistence
🔹 Communicates with the attacker’s server using encrypted messages
🔹 Drops Fickle Stealer to grab sensitive data

✅ Mitigation:

Patch your systems immediately

Restrict execution of .msc files from unknown locations

Train users to be suspicious of unsolicited IT requests

📢 Stay ahead of cyber threats — Subscribe to TheCyberScroll for quick, no-fluff cyber alerts & breakdowns.

#CyberSecurity #ZeroDay #EncryptHub #WindowsExploit #HackingNews #CVE202526633 #FickleStealer #MicrosoftTeamsHack #TheCyberScroll

Видео 🚨 Windows Zero-Day Exploit (CVE-2025-26633) | EncryptHub Hack Explained ⚠️ канала The Cyber Scroll
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять