PULSE NAME
Unveiling EncryptHub: Analysis of a multi-stage malware campaign
WHITE Larva-208 AlienVault 2025-04-07 Modified: 2025-05-07
91
IOCs
HIGH VOLUME
EncryptHub, an emerging cybercriminal entity, has been conducting multi-stage malware campaigns using trojanized applications and third-party distribution services. Their tactics include using PowerShell scripts for system data gathering, information exfiltration, and payload deployment. The threat actor prioritizes stolen credentials based on cryptocurrency ownership and corporate network affiliation. EncryptHub is developing a remote access tool called 'EncryptRAT' with plans for future distribution. Their evolving killchain involves multiple stages, including initial execution, data exfiltration, system information collection, and eventual deployment of the Rhadamanthys malware. Despite operational security mistakes, EncryptHub continues to refine their tactics, emphasizing the need for vigilant cybersecurity measures.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Kematian Stealer Rhadamanthys EncryptRAT
Indicators of Compromise (17 / 91 total)
All domain FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 08bbfd2ceb2d0272f19547f060a8b6d2ce34c8eb 2025-04-07
FileHash-SHA1 1d99d7ab6334e175148a14d724e692062f9e53ff 2025-04-07
FileHash-SHA1 32aa32baa3af74c1710764fca0e5214abbeec455 2025-04-07
FileHash-SHA1 42146e9dd1bdc415b1d9b4e036812d2ecc41e70e 2025-04-07
FileHash-SHA1 46d79522034154848935839619d622cb56297bc3 2025-04-07
FileHash-SHA1 508023b2dc96336d0f74a645817da52866b6a20f 2025-04-07
FileHash-SHA1 87c46845f57dc9ca8136b730c08b5b5916ca0ad3 2025-04-07
FileHash-SHA1 8ac8d9d390c387e8834144ca5390397db97c87b9 2025-04-07
FileHash-SHA1 a0ca753f0845b420e3f25e200b81d9936e731875 2025-04-07
FileHash-SHA1 a225bee48074feac53c7cb2f3929a41f7b4a71d3 2025-04-07
FileHash-SHA1 b0d24a6fa1af41c50e0fe11cbd266894eb45522c 2025-04-07
FileHash-SHA1 c1bd7bc905fee7f749329fbd70fd8fd37319b300 2025-04-07
FileHash-SHA1 cb9f67daff6a58a28f588d49643a0fdeb6f23bec 2025-04-07
FileHash-SHA1 d4ece3957927d4440a43a00a7c0d30ea21238809 2025-04-07
FileHash-SHA1 d8d946a6df1649972694312e299aeff3cf2afb9b 2025-04-07
FileHash-SHA1 ef5a33d30c00d1a0af0ec860146c31ff0f9bd6b6 2025-04-07
FileHash-SHA1 ffb72adff6e099a9deb418c5d40abd8cf9b12c42 2025-04-07