logo

In-Depth Analysis: Water Gamayun APT Multi-Stage Attack Uncovered

ID: 318e39e2-d7c3-583d-96b0-82525c44713f

STIX ID: report--318e39e2-d7c3-583d-96b0-82525c44713f

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-11-25

Date Updated: 2026-05-01

...
...

Technical analysis of a Water Gamayun (Russia-aligned) APT campaign: a compromised BELAY Solutions site redirected users to belaysolutions.link which served a double-extension RAR (masquerading as a PDF). The archive dropped a malicious .msc snap-in that executed Base64-encoded PowerShell via mmc.exe to download UnRAR.exe and a password-protected RAR, compile a C# helper (WinHpXN) to hide consoles and display a decoy PDF, and ultimately deploy a persistent loader (ItunesC.exe) that likely installs backdoors or stealers; several filenames and URLs are provided as IOCs though the C2 was non-responsive so the exact malware family was unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.