HomeSecurityEncryptHub team has targeted 618 organizations

The EncryptHub team has targeted 618 organizations

A hacking group tracked as “EncryptHub” (or Larva-208) has targeted at least 618 organizations worldwide with spear-phishing and social engineering attacks. The goal is to gain access to corporate networks to install info-stealer malware and ransomware.

The EncryptHub team has targeted 618 organizations

According to a report by Prodaft, EncryptHub began its malicious activities in June 2024 and has since compromised at least 618 organizations.

Once they gain access to networks, hackers install Remote Monitoring and Management (RMM) software and then info-stealers, such as Stealc and Rhadamanthys. In many cases, EncryptHub also deploys ransomware.

See also: Hackers leaked Genea patient data

Prodaft told BleepingComputer that the threat group is affiliated with RansomHub and BlackSuit, having used both ransomware encryptors in the past and likely acting as an initial access broker for the ransomware gangs or as an affiliate.

However, in many attacks, the attackers developed a custom PowerShell data encryptor, which means they also maintain their own malware, despite the fact that there may be some collaboration with the above groups.

Home access

EncryptHub appears to launch its attacks with SMS phishing, voice phishing, and fake login pages that mimic enterprise VPN products such as Cisco AnyConnect, Palo Alto GlobalProtect, Fortinet, and Microsoft 365.

Attackers typically impersonate IT support staff in their messages and state that there is a access VPN or a security issue with the target's account. They then direct the victim to a phishing site, where credentials and multi-factor authentication (MFA) tokens (session cookies) are captured in real time. Once the process is complete, the victim is redirected to the service's real domain.

See also: OpenAI blocked ChatGPT accounts of North Korean hackers

EncryptHub has purchased over 70 domains that mimic these products, such as 'linkwebcisco.com' and 'weblinkteams.com', to make the phishing pages.

Prodaft also discovered that there is another subgroup monitored as Larva-148, which helps with domain purchase, hosting management, and infrastructure setup.
It is possible that Larva-148 sells domains and phishing kits to EncryptHub, although their exact relationship has not yet been clarified.

EncryptHub info-stealer ransomware

Malware development

Once EncryptHub compromises a targeted system, it deploys various PowerShell scripts and malware to achieve persistence, remote access, data theft, and file encryption.

Initially, the attackers deceive victims to install RMM software such as AnyDesk, TeamViewer, ScreenConnect, Atera and Splashtop. This allows them to control the compromised system remotely, maintain access and proceed with lateral movement.

They then use different PowerShell scripts to deploy info-stealers (Stealc, Rhadamanthys, and Fickle Stealer) and steal data stored in web browsers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Hackers can steal a large volume of data, such as:

  • Data from various cryptocurrency wallets, including MetaMask, Ethereum Wallet, Coinbase Wallet, Trust Wallet, Opera Wallet, Brave Wallet, TronLink, Trezor Wallet and many others.
  • Configuration data for various VPN clients, including Cisco VPN Client, FortiClient, Palto Alto Networks GlobalProtect, OpenVPN, and WireGuard.
  • Data from popular password managers, including Authenticator, 1Password, NordPass, DashLane, Bitwarden, RoboForm, Keeper, MultiPassword, KeePassXC, and LastPass.
  • Files that match specific extensions or whose names contain specific keywords, such as images, RDP connection files, Word documents, Excel spreadsheets, CSV files, and certificates.

See also: Hackers can gain access to buildings – How is it done?

Finally, as we mentioned earlier, the EncryptHub team can also install ransomware and leave a ransom note for victims, which demands a ransom payment in USDT via Telegram.

Prodaft says that EncryptHub is an advanced threat actor that adapts its attacks for better effectiveness.

Protection against info-stealer malware ransomware

  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Use antivirus and malware
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using solutions email security for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Back up your data regularly
  • Stay up to date on the latest ransomware trends and tactics used by attackers

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS