PULSE NAME
Unveiling EncryptHub: Analysis of a multi-stage malware campaign
WHITE Larva-208 AlienVault 2025-04-07 Modified: 2025-05-07
91
IOCs
HIGH VOLUME
EncryptHub, an emerging cybercriminal entity, has been conducting multi-stage malware campaigns using trojanized applications and third-party distribution services. Their tactics include using PowerShell scripts for system data gathering, information exfiltration, and payload deployment. The threat actor prioritizes stolen credentials based on cryptocurrency ownership and corporate network affiliation. EncryptHub is developing a remote access tool called 'EncryptRAT' with plans for future distribution. Their evolving killchain involves multiple stages, including initial execution, data exfiltration, system information collection, and eventual deployment of the Rhadamanthys malware. Despite operational security mistakes, EncryptHub continues to refine their tactics, emphasizing the need for vigilant cybersecurity measures.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Kematian Stealer Rhadamanthys EncryptRAT
Indicators of Compromise (15 / 91 total)
All domain FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 011827ebdf113755102a47987b718587 2025-04-07
FileHash-MD5 24319498575aa15c9eef7a058e19eb97 2025-04-07
FileHash-MD5 46eae0ac01ddb2b25e366045a166f84a 2025-04-07
FileHash-MD5 5108c8cc2686bf849b48b95f71dd56e1 2025-04-07
FileHash-MD5 5488c867b16fa0ff44dc975caf8e5f8e 2025-04-07
FileHash-MD5 5ceea10d336ad0dec20eeb69758518f1 2025-04-07
FileHash-MD5 6246067a1c9a7c1359ad63476ce0dcbe 2025-04-07
FileHash-MD5 6522aad0b04cb58ab8cf30b3a8578fb1 2025-04-07
FileHash-MD5 6b1f16b8e366208a23f3eb966bd42d08 2025-04-07
FileHash-MD5 77a7b069a79ae06719db44dc3bdebb86 2025-04-07
FileHash-MD5 87792cf4bd370f483a293a23c4247c50 2025-04-07
FileHash-MD5 abaa46bc704842d6cc6f494c21546ae6 2025-04-07
FileHash-MD5 cf0514b56f6498161a3af8737d6a5cbb 2025-04-07
FileHash-MD5 e2d005af8f840f371ab2cef870dacbcf 2025-04-07
FileHash-MD5 e59a025f9310d266190b91f5330fde8d 2025-04-07