Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

EncryptHub Launches Phishing Attacks

March 7, 2025
Reading Time: 2 mins read
in Alerts
AI Tools Fuel Nonconsensual Porn Creation

EncryptHub, a financially motivated cybercriminal group, has been observed conducting sophisticated phishing campaigns to deploy information stealers and ransomware. This group primarily targets users of popular applications by distributing trojanized versions of widely used software. Active since June 2024, EncryptHub uses a variety of phishing methods including SMS phishing (smishing), voice phishing (vishing), and spear-phishing to trick victims into installing malicious software. This group, also known as LARVA-208, is affiliated with high-profile ransomware groups such as RansomHub and Blacksuit. Their attacks have led to the compromise of over 600 high-value targets, spanning multiple industries, showcasing the group’s focus on lucrative opportunities.

The group’s primary tactic involves creating phishing websites to steal VPN credentials from unsuspecting victims. Once the attackers have obtained the credentials, they impersonate IT support or helpdesk staff and request that victims enter their details on the phishing site. These phishing websites are hosted on bulletproof providers like Yalishand, making it difficult for authorities to trace them. After gaining access to the compromised systems, EncryptHub runs PowerShell scripts that deliver various information-stealing malware, including Fickle, StealC, and Rhadamanthys.

The attackers’ ultimate goal is to deploy ransomware, encrypt data, and demand a ransom, often targeting large organizations for maximum financial gain.

In addition to phishing sites, EncryptHub uses a variety of trojanized applications to gain initial access to victim systems. These applications, which appear to be legitimate, include fake versions of popular software such as QQ Talk, Google Meet, and Microsoft Visual Studio. When these applications are installed, they initiate a multi-stage process that ultimately delivers further malicious payloads, such as Kematian Stealer. This malware is designed to steal cookies and sensitive data from victims, facilitating further exploitation.

The attackers can then move laterally within the network, escalating their access and control over critical systems and data.

To expand its reach, EncryptHub has been using third-party Pay-Per-Install (PPI) services like LabInstalls to distribute malware on a larger scale. These services allow EncryptHub to pay for bulk malware installations, thereby increasing the number of targets affected by their attacks. LabInstalls charges between $10 for 100 installs and $450 for 10,000, providing EncryptHub with a cost-effective method to spread their malicious software.

The group has also been developing a new tool, EncryptRAT, a command-and-control (C2) panel that enables them to manage active infections, issue remote commands, and exfiltrate stolen data. There is even speculation that EncryptHub might commercialize this tool, reflecting their ongoing efforts to refine their tactics and expand their cybercrime operations. Organizations are urged to stay vigilant and adopt multi-layered security strategies to defend against evolving threats like those posed by EncryptHub.

Reference:
  • EncryptHub Expands Operations with Phishing Attacks and EncryptRAT Malware
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityMarch 2025
ADVERTISEMENT

Related Posts

VexTrio TDS Uses Adtech To Spread Malware

Simple Typo Breaks AI Safety Via TokenBreak

June 13, 2025
VexTrio TDS Uses Adtech To Spread Malware

VexTrio TDS Uses Adtech To Spread Malware

June 13, 2025
VexTrio TDS Uses Adtech To Spread Malware

Old Discord Links Now Lead To Malware

June 13, 2025
SmartAttack Uses Sound To Steal PC Data

SmartAttack Uses Sound To Steal PC Data

June 13, 2025
SmartAttack Uses Sound To Steal PC Data

Coordinated Brute Force Hits Tomcat Manager

June 13, 2025
SmartAttack Uses Sound To Steal PC Data

Pentest Tool TeamFiltration Hits Entra ID

June 12, 2025

Latest Alerts

Old Discord Links Now Lead To Malware

VexTrio TDS Uses Adtech To Spread Malware

Simple Typo Breaks AI Safety Via TokenBreak

Coordinated Brute Force Hits Tomcat Manager

SmartAttack Uses Sound To Steal PC Data

Pentest Tool TeamFiltration Hits Entra ID

Subscribe to our newsletter

    Latest Incidents

    Cyberattack On Brussels Parliament Continues

    Swedish Broadcaster SVT Hit By DDoS

    Major Google Cloud Outage Disrupts Web

    AI Spam Hijacks Official US Vaccine Site

    DragonForce Ransomware Hits Philly Schools

    Erie Insurance Cyberattack Halts Operations

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial