logo

ChatGPT Clues and OPSEC Errors Expose EncryptHub Ransomware Operators

ID: c94ed544-2d86-5446-b9b6-1ae037c3e6e2

STIX ID: report--c94ed544-2d86-5446-b9b6-1ae037c3e6e2

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2025-04-04

Date Updated: 2026-04-13

Author: Mandvi

...
...

EncryptHub is a financially motivated cybercriminal group linked to 600+ global incidents that operate multi-stage campaigns using trojanized applications, PowerShell scripts, custom stealers (Stealc, Rhadamanthys) and ransomware (files encrypted with an ".crypted" extension). The report highlights the group’s use of ChatGPT to assist in malware development and campaign planning, exploitation of CVEs, and significant OPSEC failures (exposed directory listings, plaintext credentials, misconfigured Telegram bots) that allowed researchers to recover IOCs (file hashes, domains, IPs) and map their TTPs; defenders are advised to monitor those IOCs and strengthen endpoint defenses and training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.