Tag: Fickle Stealer Malware

Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
News

Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware

The threat actor EncryptHub is still using a Microsoft Windows security hole that has been patched to spread harmful payloads. According to Trustwave SpiderLabs, it recently discovered an EncryptHub campaign that uses a rogue Microsoft Console (MSC) file to initiate the infection process, combining social engineering with the exploitation of a Microsoft Management Console (MMC) framework vulnerability (CVE-2025-26633, also known as MSC EvilTwin). According to Trustwave experts Nathaniel Morales and Nikita Kazymirskyi, these actions are a part of a large, continuous wave of hostile activity that combines technical exploitation and social engineering to get past security measures and take control of internal environments. The Russian hacker collective EncryptHub, also known as LARV...
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware
News

EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware

A new effort targeting Web3 developers to infect them with information-stealing malware has been linked to the financially motivated threat actor EncryptHub (also known as LARVA-208 and Water Gamayun). According to a statement provided to The Hacker News by Swiss cybersecurity firm PRODAFT, LARVA-208 has changed its strategies, enticing victims with employment offers or requests for portfolio reviews through the use of phony AI platforms (such as Norlax AI, which imitates Teampilot). Although the gang has a history of utilizing ransomware, the most recent discoveries show that its strategies have changed and that it has diversified its revenue streams by harvesting cryptocurrency wallet data using stealer software. The emphasis on Web3 developers by EncryptHub is not coincidental...