BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

EncryptHub Targets Web3 Devs with Fake AI Job Offers, Stealer Malware

EncryptHub Targets Web3 Developers with Info-Stealing Malware and Launches New Ransomware Attacks

  • The group known as EncryptHub is targeting Web3 developers with information-stealing Malware via fake AI platforms.
  • Attackers use deceptive job offers and portfolio review requests to lure victims.
  • They deliver malware disguised as audio driver updates, aiming to gain access to cryptocurrency wallets and sensitive credentials.
  • New Ransomware strains such as KAWA4096 and Crux have emerged, targeting organizations in the United States and Japan.
  • Ransomware groups use legitimate Windows tools to avoid detection and disable system recovery features.

A threat actor identified as EncryptHub, also known as LARVA-208 and Water Gamayun, has launched a new campaign against Web3 developers. According to Cybersecurity company PRODAFT, the group targets these developers using fake Artificial Intelligence platforms and job-related pretexts to infect devices with information-stealing malware.

- Advertisement -

Investigators report that EncryptHub sends job offers and portfolio review requests through platforms like X (formerly Twitter), Telegram, and a Web3 job board named Remote3. The campaign focuses on freelancers and developers involved in decentralized crypto projects who often handle sensitive wallets and smart contracts. Once in contact, attackers guide victims through fake interviews using Google Meet, then instruct them to join a meeting on platforms such as Norlax AI, ultimately leading victims to download malicious files.

When victims click on meeting links, they are prompted for an email address and invitation code, then shown a fake error message about outdated audio drivers. Accepting this prompt downloads a file disguised as a Realtek audio driver. This file executes PowerShell commands to install a malware known as Fickle Stealer, which collects information from crypto wallets and development environments and sends the data to an external server called SilentPrism.

PRODAFT stated, “The threat actors distribute infostealers like Fickle through fake AI applications, successfully harvesting cryptocurrency wallets, development credentials, and sensitive project data.” The company noted a shift in criminal methods, describing increased reliance on data theft for direct monetization or resale in illicit markets.

Trustwave SpiderLabs recently described a new ransomware named KAWA4096, which has attacked at least 11 companies—mainly in the United States and Japan—since June 2025. The group uses a technique that processes files in parallel, rapidly encrypting files on shared network drives. Investigators have not identified the method used to gain initial access.

- Advertisement -

Another ransomware called Crux has emerged this month. According to Huntress, Crux attackers frequently use stolen remote desktop credentials and legitimate Windows tools such as svchost.exe and bcdedit.exe to hide activity and disable system recovery.

Huntress advises, “Continual monitoring for suspicious behavior using these processes via endpoint detection and response (EDR) can help suss out threat actors in your environment.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

GhostAction compromises two top GitHub devs, hits 340 repos

Two high-profile open-source maintainer accounts were compromised, pushing a malicious workflow into over 340...

OCC fines AmEx $350M over $13B money laundering

The OCC found American Express National Bank processed approximately $13 billion in suspected trade-based...

AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw...

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading