EncryptHub is a financially motivated Russian threat actor tracked under aliases including LARVA-208 and Water Gamayun. The actor emerged prominently in 2024 and has been associated with credential theft, access brokering, information-stealing malware campaigns, and ransomware delivery. Reporting also links a related subgroup, LARVA-148, to domain acquisition and supporting attack infrastructure. EncryptHub has targeted enterprises, government environments, finance, telecom, defense, manufacturing, and Web3 developers, and has also compromised gaming distribution channels to deliver stealers to end users. EncryptHub is notable for blending social engineering with technical exploitation. A major tradecraft theme is abuse of Microsoft Management Console through CVE-2025-26633, known as MSC EvilTwin. In these campaigns, the actor has used rogue or paired benign and malicious MSC files, often delivered through phishing, fake IT support interactions, Microsoft Teams messages, videoconferencing lures, or abuse of legitimate hosting platforms. Execution chains commonly rely on PowerShell for staging, reconnaissance, persistence, command-and-control, and payload delivery. Observed follow-on tooling includes SilentPrism, DarkWisp, SilentCrystal, Fickle Stealer, and Golang backdoors that support SOCKS5 tunneling. The actor has also used DLL sideloading and deceptive filesystem path manipulation to evade defenses. The group’s operations emphasize credential harvesting, browser and cookie theft, cryptocurrency wallet theft, system reconnaissance, persistence, and exfiltration. Campaigns aimed at Web3 developers and Steam users distributed information stealers including custom malware and commodity stealers. In one widely reported intrusion pattern, EncryptHub used staged PowerShell loaders and encrypted tasking to maintain control and deploy additional payloads. Reporting also attributes lateral movement in enterprise environments to the actor, including use of built-in administrative tools after initial compromise. EncryptHub has been linked to large-scale victimization, with hundreds of organizations reportedly compromised globally. The actor’s operational profile aligns primarily with cybercrime rather than state espionage, despite being described in some reporting as Russia-aligned. High-confidence reporting consistently supports financial motivation, credential theft, malware delivery, access monetization, and ransomware-related activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used malicious Steam-hosted game content to deliver malware for credential theft, browser data theft, cookie theft, and cryptocurrency wallet theft.
Financially motivated group targeting Web3 developers using fake AI platforms and social engineering lures to deploy stealer malware and harvest data from cryptocurrency wallets. The content also notes the group has a history of deploying ransomware.
Referenced only as an associated analytic story; no specific threat actor activity, targeting, malware, or operations are described in the content.
Financially motivated actor using a mix of social engineering and exploitation (notably CVE-2025-26633 / MSC EvilTwin) to deliver stealer malware (e.g., Fickle Stealer) and target Web3 developers via fake AI platforms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.