HomeSecurityEncryptHub hacker reported two vulnerabilities to Microsoft

EncryptHub hacker reported two vulnerabilities to Microsoft

Microsoft said the hacker, who goes by the name EncryptHub, discovered and reported two Windows security vulnerabilities last month, creating confusion about his activity, which has been linked to hundreds of cyberattacks so far.

EncryptHub Microsoft vulnerabilities

In a new extensive analysis published by Outpost24 KrakenLabs, the company revealed some details about the cybercriminal, who, about 10 years ago, left his hometown of Kharkiv, Ukraine, and moved to a new location near the Romanian coast.

The discovery of the two Windows security vulnerabilities was linked to someone called “SkorikARI with SkorikARI,” which is believed to be another username used by EncryptHub. The vulnerabilities were patched by Microsoft as part of the March Patch Tuesday:

  • CVE-2025-24061 (CVSS score: 7.8): Vulnerability that allows bypass of Microsoft Windows Mark-of-the-Web (MotW) security features
  • CVE-2025-24071 (CVSS score: 6.5): Spoofing vulnerability located in Microsoft Windows File Explorer

See also: Port of Seattle: Data breach affects 90,000 people

The EncryptHub hacker is also known as LARVA-208 and Water Gamayun and gained attention in mid-2024 when he exploited a fake WinRAR to distribute malware.

In recent weeks, it has also been linked to the exploitation of another zero-day vulnerability in the Microsoft Management Console (CVE-2025-26633, CVSS score: 7.0) to distribute information stealers and backdoors.

According to PRODAFT, it is estimated that EncryptHub has breached over 618 organizations across multiple industries in the last nine months.

“All data analyzed during our investigation points to the actions of a single individual,” said Lidia Lopez, Senior Threat Intelligence Analyst at Outpost24. “However, we cannot rule out the possibility of collaboration with other threat actors.”

In one of the Telegram channels, used to track infection statistics, there was another user with admin rights, indicating possible collaboration or assistance from others without clear group involvement.

See also: Coinbase fixes 2FA account activity log

Outpost24 said it was able to piece together EncryptHub's online footprint from "theattacker's self-infections due to poor operational security practices," revealing new aspects of its infrastructure and tools.

The hacker is believed to have kept a low profile after moving to a location near Romania, studying computer science on his own by taking online courses, while looking for computer-related jobs.

His activity, however, abruptly stopped in early 2022, at the onset of the Russia-Ukraine war. That said, Outpost24 said it found evidence suggesting that he was imprisoned around the same period.

“Upon release, he continued his job search, this time offering freelance web and app development services,” the company said in the report. “But the pay was likely not enough, and after briefly trying bug bounty programs with little success, we believe he turned to cybercrime in the first half of 2024.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

EncryptHub hacker reported two vulnerabilities to Microsoft

One of EncryptHub's first ventures into the cybercrime was Fickle Stealer, which was first documented by Fortinet FortiGuard Labs in June 2024 as information-stealing malware distributed through multiple channels.

It is also said that EncryptHub relied extensively on ChatGPT to create malware and translate emails and messages.

“The EncryptHub case highlights how poor operational security remains one of the most critical weaknesses for cybercriminals,” Lopez noted. “Despite the technical sophistication, fundamental errors—such as password reuse, exposed infrastructure, and the mixing of personal and criminal activity—ultimately led to its exposure.”

See also: Phishing emails impersonate E-ZPass and other toll services

Also, the recent vulnerability report at Microsoft is a very interesting case, and quite typical of the gray ethical landscape we often encounter in the cybersecurity space.

The fact that “EncryptHub” reported and actually helped with the identification of two vulnerabilities in Windows, shows this double face that many of the so‑called “lone wolves” in cyberspace have. Not few are those who started from the “gray” or even the “black” part of hacking and then jumped to official, “white” careers. The opposite also happens — the identity clash is real. It remains to see how EncryptHub will continue to move.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS