EvilTwin - Vulnerability

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 26, 2025
Last Seen
June 30, 2026

EvilTwin is a recently disclosed vulnerability in MSC software components that threat actors are actively exploiting to inject or deliver malicious code.

EvilTwin is a vulnerability tracked across 2 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity June 30, 2026.

Overview

EvilTwin is a recently disclosed vulnerability in MSC software components that threat actors are actively exploiting to inject or deliver malicious code. The Gamayun APT group, including a Water Gamayun variant, is leveraging EvilTwin flaws to weaponize the vulnerability, underscoring its potential for payload delivery and remote access. The rapid, multi-article activity on a single day signals it as an actionable and significant cybersecurity risk that defenders should monitor closely and prioritize for patching and detection.

Related Threat Clusters

Recent Intelligence Reports

  • Kali Linux 2026.2 released with 9 new tools, NetHunter updates — Bleepingcomputer · June 30, 2026
  • Water Gamayun APT Hackers Exploit MSC EvilTwin Vulnerability to Inject Malicious Code — Cybersecuritynews · November 26, 2025
  • Gamayun APT Exploits MSC EvilTwin Flaw to Deploy Malicious Code — Cyberpress · November 26, 2025
  • Gamayun APT Exploits New MSC EvilTwin Vulnerability to Deliver Malicious Payloads — Gbhackers · November 26, 2025

Frequently asked questions

What is EvilTwin?

EvilTwin is a recently disclosed vulnerability in MSC software components that threat actors are actively exploiting to inject or deliver malicious code.

Is EvilTwin still active?

The most recent intelligence report mentioning EvilTwin on ThreatCluster is dated June 30, 2026. Activity was first observed November 26, 2025, giving a tracked span from then to June 30, 2026.

What is EvilTwin associated with?

Across ThreatCluster reporting, EvilTwin most frequently co-occurs with Gamayun, Gamayun APT, Water Gamayun, Water Gamayun APT Hackers, Malware, among 12 tracked related entities.

What are the latest developments involving EvilTwin?

The most significant recent cluster is “Gamayun APT Targets MSC EvilTwin Vulnerability for Cyberattack” (3 articles · Updated November 26, 2025). EvilTwin appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on EvilTwin?

EvilTwin appears in 4 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown