Skip to main content
Mallory
Financially Motivated10 malware familiesExploits CVEs in the wild

EncryptHub

Also known asEncryptHubLarva-208Water Gamayun

EncryptHub is a financially motivated Russian threat actor, also tracked as LARVA-208 and Water Gamayun. The content also describes Water Gamayun as a Russia-aligned APT and attributes the same activity cluster to EncryptHub/LARVA-208. EncryptHub has been linked to malware campaigns, credential theft, and access brokering, and gained prominence in mid-2024. The actor has targeted Web3 developers, enterprise and government networks, and organizations in sectors including telecom, finance, defense, and manufacturing. Reporting in the content states that at least 618 organizations worldwide were compromised in campaigns attributed to EncryptHub. The actor has also abused Steam to distribute malware by compromising game titles such as Chemia. Observed tradecraft includes social engineering, spear-phishing, smishing, vishing, fake IT-support interactions over Microsoft Teams, videoconferencing lures, fraudulent login pages impersonating Microsoft 365, Cisco AnyConnect, and other corporate VPN services, and the use of remote monitoring and management tools such as AnyDesk and TeamViewer for access and lateral movement. The actor has repeatedly exploited the Windows Microsoft Management Console vulnerability CVE-2025-26633 ("MSC EvilTwin") using rogue or paired benign/malicious .msc files to trigger code execution. Related activity includes abuse of compromised or trusted platforms such as Brave Support, use of deceptive paths such as "C:\Windows \System32", PowerShell-based multi-stage loaders, persistence, AES-encrypted tasking, SOCKS5 proxy tunneling, DLL sideloading via a legitimate Symantec ELAM binary, and use of built-in administrative tools for lateral movement. Malware and tooling directly associated in the content include Fickle Stealer, SilentPrism, DarkWisp, SilentCrystal, a Golang-based SOCKS5 backdoor, Rhadamanthys, Stealc, HijackLoader, and Vidar. In the Chemia Steam case, EncryptHub added HijackLoader, which downloaded Vidar, and also deployed its custom Fickle Stealer, which steals credentials, browser data, cookies, and cryptocurrency wallets. Other reporting in the content states the actor used PowerShell scripts to deliver Rhadamanthys, Stealc, and Fickle Stealer, and exfiltrated cryptocurrency wallet data, VPN client configuration data, password manager data, and files matching selected extensions and keywords. A custom PowerShell-based data encryptor is also mentioned. The content references a Larva-148 subgroup in connection with EncryptHub activity, with analysis suggesting it may supply domains and phishing kits.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics23 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1189
Drive-by Compromise
TA0002
Execution
3 techniques
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1203
Exploitation for Client Execution
T1204×2
User Execution
T1204.002
Malicious File
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1027.004
Compile After Delivery
T1027.005
Indicator Removal from Tools
T1036
Masquerading
T1218
System Binary Proxy Execution
T1218.014
MMC
T1564
Hide Artifacts
TA0006
Credential Access
4 techniques
T1528
Steal Application Access Token
T1539
Steal Web Session Cookie
T1552
Unsecured Credentials
T1552.004
Private Keys
T1555
Credentials from Password Stores
TA0007
Discovery
1 technique
T1016
System Network Configuration Discovery
TA0009
Collection
2 techniques
T1005
Data from Local System
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
1 technique
T1105×2
Ingress Tool Transfer
IOCS

Observables

18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping19

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal10

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables18

Domains, IPs, and hashes tied to this actor, refreshed continuously.