EvilTwin is a recently disclosed vulnerability in MSC software components that threat actors are actively exploiting to inject or deliver malicious code.
EvilTwin is a vulnerability tracked across 2 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity June 30, 2026.
EvilTwin is a recently disclosed vulnerability in MSC software components that threat actors are actively exploiting to inject or deliver malicious code. The Gamayun APT group, including a Water Gamayun variant, is leveraging EvilTwin flaws to weaponize the vulnerability, underscoring its potential for payload delivery and remote access. The rapid, multi-article activity on a single day signals it as an actionable and significant cybersecurity risk that defenders should monitor closely and prioritize for patching and detection.
The Gamayun APT, linked to the Russia-aligned Water Gamayun group, has exploited a newly identified MSC EvilTwin vulnerability to deploy malicious code. This attack highlights the ongoing threat posed by advanced…
On June 29, 2026, Offensive Security released Kali Linux 2026.2, introducing nine new tools and significant improvements to VM boot times. The update includes enhancements to the GNOME 50 and KDE Plasma 6.6 desktop…
EvilTwin is a recently disclosed vulnerability in MSC software components that threat actors are actively exploiting to inject or deliver malicious code.
The most recent intelligence report mentioning EvilTwin on ThreatCluster is dated June 30, 2026. Activity was first observed November 26, 2025, giving a tracked span from then to June 30, 2026.
Across ThreatCluster reporting, EvilTwin most frequently co-occurs with Gamayun, Gamayun APT, Water Gamayun, Water Gamayun APT Hackers, Malware, among 12 tracked related entities.
The most significant recent cluster is “Gamayun APT Targets MSC EvilTwin Vulnerability for Cyberattack” (3 articles · Updated November 26, 2025). EvilTwin appears across 2 threat clusters in total, listed above with sources.
EvilTwin appears in 4 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.