RST TI Report Digest: 17 Mar 2025
ID: c67720d7-89bd-56ba-a9de-70bd0eb532f9
STIX ID: report--c67720d7-89bd-56ba-a9de-70bd0eb532f9
Feed Name: RST Cloud Blog
EncryptHub is a cybercriminal organization conducting a multi-stage malware campaign that trojanizes commonly used applications to deliver payloads, uses PowerShell and third-party automation to deploy malware, and focuses on exfiltrating sensitive data (cryptocurrency wallets and browser-stored credentials); the report enumerates active infrastructure and numerous IoCs (IP addresses, domains, URLs, and many SHA-256 hashes) and highlights the group's ongoing development of a remote access tool dubbed "EncryptRAT."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
