Tuesday, 31 March

Tuesday, 31 March2026

EncryptHub Phishes Web3 Developers with Fake AI Platforms to Install Crypto-Stealing Malware

By Isha
EncryptHub Phishes Web3 Developers with Fake AI Platforms to Install Crypto-Stealing Malware
The financially motivated threat group EncryptHub (aka LARVA‑208/Water Gamayun) is targeting Web3 developers via spoofed AI platforms like "Norlax AI" and "Teampilot." Using fake job offers or portfolio reviews, attackers lure victims into downloading malicious software disguised as audio drivers. This triggers the installation of Fickle Stealer, which harvests cryptocurrency wallets, dev credentials, and project data for exfiltration. Developers should use endpoint protection and authenticity.

Download TechShots

IT Trends Move Fast. Stay Faster.

Share your insights

Subscribe To Our Newsletter.

Full Name
Email