Sunday, October 4, 2026

LARVA-208 Hackers Compromise 618 Organizations Stealing Logins and Deploying Ransomware

A newly identified cybercriminal group, LARVA-208, also known as EncryptHub, has successfully infiltrated 618 organizations globally since June 2024, leveraging advanced social engineering techniques to steal credentials and deploy ransomware.

According to reports from cybersecurity firms CATALYST and Prodaft, the group has demonstrated a high level of sophistication in its operations, targeting corporate networks through spear-phishing campaigns that utilize smishing (SMS phishing) and vishing (voice phishing).

Sophisticated Social Engineering Tactics Exploited

LARVA-208’s modus operandi involves impersonating IT personnel to deceive employees into divulging VPN credentials or installing Remote Monitoring and Management (RMM) software such as AnyDesk, TeamViewer, or Atera.

The attackers have registered over 70 domain names mimicking popular VPN services like Cisco AnyConnect, Palo Alto GlobalProtect, and Fortinet to enhance the credibility of their phishing campaigns.

By harvesting one-time passcodes (OTPs) during real-time interactions, the group bypasses multifactor authentication (MFA) measures and redirects victims to legitimate login pages to avoid suspicion.

Once access is gained, LARVA-208 deploys custom-developed PowerShell scripts to install information-stealing malware such as StealC, Rhadamanthys, and Fickle Stealer.

LARVA-208
Attack flow showing LARVA-208 obtaining Microsoft account information.

According to Catalyst, these tools extract sensitive data, including browser-stored credentials, session cookies, and system information.

The stolen data is exfiltrated to Command-and-Control (C2) servers controlled by the attackers.

Additionally, the group targets cryptocurrency wallets and password managers, further amplifying the impact of their attacks.

The final stage of LARVA-208’s operations involves deploying ransomware payloads to encrypt files on compromised systems.

The group’s proprietary ransomware, Locker.ps1, utilizes AES encryption to lock files and appends a “.crypted” extension.

Victims are left with a ransom note instructing them to contact the attackers via Telegram for payment in cryptocurrency.

LARVA-208
The ransom note left on the victim device after the encryption process is finished.

The group has also been linked to other ransomware strains such as RansomHub and BlackSuit.

Ransomware Deployment Causes Widespread Operational Disruptions

In some cases, LARVA-208 exploits vulnerabilities in Microsoft Teams links by abusing open redirect parameters on Microsoft’s domains.

This allows them to intercept user credentials without creating fake login pages.

The group’s reliance on bulletproof hosting providers for phishing sites further complicates takedown efforts.

The scale of these breaches has resulted in significant operational disruptions for affected organizations.

Experts warn that LARVA-208 exemplifies the growing sophistication of cyber threats targeting high-value entities.

By combining advanced obfuscation techniques with tailored social engineering tactics, the group has demonstrated remarkable efficacy in evading detection and compromising critical systems.

Cybersecurity firms emphasize the need for enhanced awareness and robust security measures to counteract such threats.

As LARVA-208 continues its campaigns, organizations must remain vigilant against evolving attack vectors designed to exploit human vulnerabilities and technical defenses alike.

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

A newly identified IoT botnet, Cling, disguises its command-and-control...

Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands

Microsoft Threat Intelligence has identified a ClickFix campaign in...

Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands

GitLab has issued emergency security updates for a critical...

AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials

AWS has released security fixes for four vulnerabilities affecting...

Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update

Citrix NetScaler administrators report repeated appliance crashes and forced...

Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF

A newly released PlayStation 5 jailbreak chain, called Relapse,...

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and...

Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History database contains a lesser-known tagging artifact that...

Related Articles

Recent News