logo

EncryptHub breaches 618 orgs to deploy infostealers, ransomware

ID: f86bc8b4-da39-5775-aed0-2d156fcc05e7

STIX ID: report--f86bc8b4-da39-5775-aed0-2d156fcc05e7

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-02-26

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

**Executive summary:** EncryptHub (tracked as Larva-208) is a sophisticated financially motivated threat actor active since June 2024 that uses SMS/voice spear-phishing and fake VPN login pages to harvest credentials and MFA session tokens, then deploys RMM tools, multiple infostealers, and a custom PowerShell-based encryptor (files appended with ".crypted") across at least 618 organizations, demanding USDT via Telegram.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.