Monday, 21 July

Monday, 21 July2025

EncryptHub Phishes Web3 Developers with Fake AI Platforms to Install Crypto-Stealing Malware

EncryptHub Phishes Web3 Developers with Fake AI Platforms to Install Crypto-Stealing Malware
The financially motivated threat group EncryptHub (aka LARVA208/Water Gamayun) is targeting Web3 developers via spoofed AI platforms like "Norlax AI" and "Teampilot." Using fake job offers or portfolio reviews, attackers lure victims into downloading malicious software disguised as audio drivers. This triggers the installation of Fickle Stealer, which harvests cryptocurrency wallets, dev credentials, and project data for exfiltration. Developers should use endpoint protection and authenticity.

Subscribe To Our Newsletter.

Full Name
Email