'EncryptHub' OPSEC Failures Reveal TTPs & Big Plans
ID: 56aeed45-c573-5097-8bea-6e0944eca88e
STIX ID: report--56aeed45-c573-5097-8bea-6e0944eca88e
Feed Name: Dark Reading
Researchers investigated EncryptHub (Larva-208), an individual threat actor credited with compromising more than 600 organizations via targeted phishing, Trojanized installers, infostealers, and remote access tools; findings reveal multiple malware artifacts (payload.ps1, runner.ps1, EncryptRAT, Rhadamanthys, Kematian/Kematian Stealer), use of PPI services, OPSEC failures exposing logs and binaries, and strong indicators the actor may sell access or operate as an initial access broker rather than solely conducting ransomware operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
