EncryptHub, also tracked as LARVA-208 and Water Gamayun, is a financially motivated Russian cybercriminal actor associated with credential theft, information-stealing malware, initial-access brokering, and ransomware distribution. It gained prominence in mid-2024 and has compromised hundreds of organizations worldwide. Its targets include enterprise and government networks, telecommunications, financial services, defense, manufacturing, and technology professionals, including Web3 developers. Associated operations have involved LARVA-148, a related cluster responsible for domain acquisition and attacks. EncryptHub uses phishing and social engineering, including fake software-download sites, AI platforms, recruitment offers, and support impersonation. It has exploited CVE-2025-26633, known as MSC EvilTwin, to bypass Microsoft Management Console security controls and execute malicious code through crafted console documents. Its attack chains employ trusted Windows binaries, layered and obfuscated PowerShell, decoy documents, and password-protected archives to deliver backdoors and stealers. Associated malware includes SilentPrism, DarkWisp, and its custom Fickle Stealer. EncryptHub also compromised the Chemia game distributed through Steam, adding HijackLoader to deliver Vidar and subsequently distributing Fickle Stealer. Its information-stealing operations harvest credentials, browser data, session cookies, and cryptocurrency-wallet information, while backdoor activity supports persistent access and remote command execution. EncryptHub has used ChatGPT for malicious-code generation and infrastructure automation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an associated analytic story; no actor-specific operation or behavior is described.
Named only through an associated analytic story; the reference provides no actor-specific operational details.
Mentioned through an associated analytic story; the supplied content provides no actor-specific operational details.
Named only in associated analytic-story metadata; no actor-specific operations are described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.