EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware
3 Articles
3 Articles


EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware
The financially motivated threat actor known as EncryptHub (aka LARVA-208 and Water Gamayun) has been attributed to a new campaign that's targeting Web3 developers to infect them with information stealer malware. "LARVA-208 has evolved its tactics, using fake AI platforms (e.g., Norlax AI, mimicking Teampilot) to lure victims with job offers or portfolio review requests," Swiss cybersecurity
Digital security is constantly facing new challenges, and one of the most recent and worrying involves the use of GitHub as a platform for distributing malware. Talos researchers, Cisco's threat intelligence team, detected a malware-as-a-service (MaaS) operation that leveraged GitHub's public accounts to spread malicious programs. Below, we explore this case and what it involves for organizations that rely on cloud services for their development…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium