#EncryptHub
A threat actor called EncryptHub has compromised a game on Steam to distribute info-stealing malware to unsuspecting users downloading the title.

#Gaming #PCGaming #Steam #TechNews #PC #SteamOS #Valve #GameNews #Technology #Cybersecurity #PCGames #Featured #TopStories #News #GameDev #IndieDev
July 28, 2025 at 2:43 PM
EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research.
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research.
www.bleepingcomputer.com
April 7, 2025 at 9:39 PM
A threat actor called EncryptHub has compromised a game on Steam to distribute info-stealing malware to unsuspecting users downloading the title.
Hacker sneaks infostealer malware into early access Steam game
A threat actor called EncryptHub has compromised a game on Steam to distribute info-stealing malware to unsuspecting users downloading the title.
www.bleepingcomputer.com
July 24, 2025 at 4:50 PM
Outpost24 says the EncryptHub cybercrime group has left exposed a trove of internal servers

-stealer logs
-malware executables
-PowerShell scripts
-Telegram bot configurations used for data exfiltration
-campaign tracking

outpost24.com/blog/unveili...
Unveiling EncryptHub: Analysis of a multi-stage malware campaign
Learn what our threat intelligence researchers have uncovered about a new threat actor using multi-stage malware: EncryptHub.
outpost24.com
March 6, 2025 at 4:29 PM
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware

thehackernews.com/2025/08/russ...
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
EncryptHub exploits CVE-2025-26633 with social engineering and rogue MSC files, delivering Fickle Stealer malware.
thehackernews.com
August 17, 2025 at 11:16 PM
Microsoft Teams Under Increasingly Under Fire. EncryptHub Compromised Corporate Networks with Malware www.redhotcyber.com/en/post/micr...
Microsoft Teams Under Increasingly Under Fire. EncryptHub Compromised Corporate Networks with Malware
EncryptHub, a Russian-linked threat group, uses social engineering and technical exploitation to compromise corporate networks with malware.
www.redhotcyber.com
August 18, 2025 at 6:10 AM
A threat actor tracked as 'EncryptHub,' aka Larva-208,  has been targeting organizations worldwide with spear-phishing and social engineering attacks to gain access to corporate networks.
EncryptHub breaches 618 orgs to deploy infostealers, ransomware
A threat actor tracked as 'EncryptHub,' aka Larva-208,  has been targeting organizations worldwide with spear-phishing and social engineering attacks to gain access to corporate networks.
www.bleepingcomputer.com
February 26, 2025 at 3:31 PM
A threat actor known as EncryptHub has been linked to Windows zero-day attacks exploiting a Microsoft Management Console vulnerability patched this month.
EncryptHub linked to zero-day attacks targeting Windows systems
A threat actor known as EncryptHub has been linked to Windows zero-day attacks exploiting a Microsoft Management Console vulnerability patched this month.
www.bleepingcomputer.com
March 25, 2025 at 4:51 PM
Unmasking EncryptHub: Help from ChatGPT

outpost24.com/blog/unmaski...
Unmasking EncryptHub: Help from ChatGPT & OPSEC blunders
Understand EncryptHub’s cybercrime journey and how he used ChatGPT as an accomplice, uncovering the methods behind his actions.
outpost24.com
April 7, 2025 at 1:18 PM
Prodaft has published a profile on LARVA-208 (EncryptHub), a known affiliate of the RansomHub and Blacksuit ransomware operations.

The group is known to run phishing pages targeting enterprise VPN login pages.

catalyst.prodaft.com/public/repor...
February 25, 2025 at 2:29 PM
EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research. #bugbounty #CyberAlerts
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling t...
www.bleepingcomputer.com
April 9, 2025 at 2:13 AM
Unmasking EncryptHub: Help from ChatGPT and Opsec Blunders

#ai #chatgpt #gpt
Unmasking EncryptHub: Help from ChatGPT and Opsec Blunders
outpost24.com
April 8, 2025 at 6:39 AM
EncryptHub, an affiliate of RansomHub, was behind recent MMC zero-day patched this month by Microsoft

www.trendmicro.com/en_us/resear...
CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code an...
www.trendmicro.com
March 25, 2025 at 2:46 PM
The controversial case of the threat actor EncryptHub
The controversial case of the threat actor EncryptHub
Microsoft credited controversial actor EncryptHub, a lone actor with ties to cybercrime, for reporting two Windows flaws.
buff.ly
April 8, 2025 at 5:42 PM
Microsoft rewarded EncryptHub, a prolific hacker (618+ breaches), for responsibly disclosing two Windows vulnerabilities (CVE-2025-24061 & CVE-2025-24071). Outpost24 suggests a lone actor with a mixed past, active until 2022, possibly imprisoned, and recently returned.#EncryptHubReward
April 5, 2025 at 6:04 PM
EncryptHub breaches 618 orgs to deploy infostealers, ransomware

A threat actor tracked as 'EncryptHub,' aka Larva-208,  has been targeting organizations worldwide with spear-phishing and social engineering attacks to gain access to corporate networks. [...]

#hackernews #news
EncryptHub breaches 618 orgs to deploy infostealers, ransomware
A threat actor tracked as 'EncryptHub,' aka Larva-208,  has been targeting organizations worldwide with spear-phishing and social engineering attacks to gain access to corporate networks. [...]
www.bleepingcomputer.com
February 27, 2025 at 3:39 PM
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
thehackernews.com
August 16, 2025 at 6:08 AM
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware
thehackernews.com
July 20, 2025 at 4:35 PM
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware thehackernews.com/2025/08/russ...
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
EncryptHub exploits CVE-2025-26633 with social engineering and rogue MSC files, delivering Fickle Stealer malware.
thehackernews.com
August 16, 2025 at 1:28 PM