EncryptHub is a malware-associated cybercriminal persona and malware name referenced in 2025 reporting as being tied to credential theft, access brokering, phishing-driven intrusions, and ransomware activity. The content describes EncryptHub as financially motivated and linked to sophisticated phishing campaigns used to collect credentials and distribute ransomware. It is also described as part of the arsenal associated with the Russia-aligned Water Gamayun threat cluster, alongside SilentPrism, DarkWisp, and Rhadamanthys; in one reported campaign, the final payload could not be confirmed because C2 infrastructure was non-responsive, but EncryptHub was assessed as one of the plausible malware families that may have been installed. Additional reporting cited in the content states that EncryptHub relied on the MSC EvilTwin loader exploiting CVE-2025-26633 as part of its custom malware arsenal. The persona “EncryptHub” is further described as long tied to malware campaigns, credential theft, and access brokering, and as being known by aliases including SkorikARI and LARVA-208. The content also states that EncryptHub distributed malware via spoofed WinRAR websites, used Telegram bots and ChatGPT in operations, and exposed its own infrastructure through OPSEC failures. High-confidence targeting details in the content indicate activity affecting enterprise and government networks, with reporting also claiming compromises of high-value targets across Europe and Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Analyzing the ChatGPT conversation history, we found that the user made CVE-related queries(CVEs queried by ChatGPT: CVE-2025–26633, CVE-2025–24983) under his name. | EncryptHub is known to be a financially motivated threat actor that uses sophisticated phishing campaigns to collect credentials and distribute ransomware.
Analyzing the ChatGPT conversation history, we found that the user made CVE-related queries(CVEs queried by ChatGPT: CVE-2025–26633, CVE-2025–24983) under his name. | EncryptHub is known to be a financially motivated threat actor that uses sophisticated phishing campaigns to collect credentials and distribute ransomware.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
EncryptHub is known to be a financially motivated threat actor that uses sophisticated phishing campaigns to collect credentials and distribute ransomware.
"However, Water Gamayun’s arsenal includes EncryptHub, SilentPrism, DarkWisp, and Rhadamanthys, so it is highly likely that any of these malware could have been installed."
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware involved in multi-stage attacks targeting enterprises and individuals.
EncryptHub is a threat actor and malware developer known for credential theft, access brokering, and distributing malware through spoofed websites. The actor also engages in legitimate vulnerability disclosure, blurring the line between cybercrime and security research.
Referenced as part of Water Gamayun’s malware arsenal; potentially deployed as a backdoor or information-stealing payload in the described intrusion chain, but not confirmed in this specific case due to non-responsive C2.
Ransomware-associated operation using phishing for credential theft and ransomware delivery; also suffered OPSEC failures exposing infrastructure and use of ChatGPT in development and postings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.