Sunday, 18 January

Monday, 21 July2025

EncryptHub Phishes Web3 Developers with Fake AI Platforms to Install Crypto-Stealing Malware

EncryptHub Phishes Web3 Developers with Fake AI Platforms to Install Crypto-Stealing Malware
The financially motivated threat group EncryptHub (aka LARVA‑208/Water Gamayun) is targeting Web3 developers via spoofed AI platforms like "Norlax AI" and "Teampilot." Using fake job offers or portfolio reviews, attackers lure victims into downloading malicious software disguised as audio drivers. This triggers the installation of Fickle Stealer, which harvests cryptocurrency wallets, dev credentials, and project data for exfiltration. Developers should use endpoint protection and authenticity.

Download the TechShots App

IT Trends Move Fast. Stay Faster.

Subscribe To Our Newsletter.

Full Name
Email