logo

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

ID: f5e09666-ea51-58a4-b42e-b14f3231e690

STIX ID: report--f5e09666-ea51-58a4-b42e-b14f3231e690

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2025-04-04

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

EncryptHub, a criminal threat actor, has been exposed after OPSEC failures revealed its infrastructure, malware tooling (including EncryptRAT), and active campaigns. The group uses trojanized legitimate-looking applications to run PowerShell scripts that steal credentials and deploy additional payloads (stealers and ransomware); researchers recovered malware hashes, domains (e.g., 0xffsec.net, vexio.io), and IPs (e.g., 206.166.251.99). EncryptHub notably leveraged ChatGPT for malware development, C2 configuration, and social engineering, and its operational mistakes (directory listings, plaintext 2FA backup codes, password reuse) enabled deeper attribution and analysis. Organizations are advised to monitor the provided IOCs and strengthen endpoint and multi-factor defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.