Unmasking EncryptHub: Help from ChatGPT & OPSEC blunders Research & Threat Intel Last updated: 03 Apr 2025 This is the second part of Outpost24’s KrakenLabs investigation into EncryptHub, an up-and-coming cybercriminal who has been gaining popularity in recent months and is heavily expanding and evolving operations at the time of writing. We’ve already published one article explaining EncryptHub’s campaigns and TPPs, infrastructure, infection methods, and targets. This article will follow a different approach. We’ll explore EncryptHub’s last decade online with a particular focus on his one-year-old foray into cybercrime, the OPSEC mistakes he’s made along the way, and how he used ChatGPT as a faithful accomplice throughout. This way, we hope to give you a human image beyond the amorphous dark entity that the generic tag of ‘Threat Actor’ usually gives. Who is EncryptHub? When people think of cybercriminals, they tend to imagine high-tech, government-backed teams and elite hackers using cutting-edge technology. However, many hackers are normal people who at some point decided to follow a dark path. Due to OPSEC errors (detailed later) we were able to learn a lot about Encrypthub, most of which will remain private. And to be clear, the purpose of this section is not to humiliate or dox the individual. It’s simply to shed light on the fact most cybercriminals are ordinary humans that lead mostly ordinary lives. Early years What follows is a brief account of EncryptHub’s life constructed from a cursory glance of his online activity. It is by no means exhaustive nor verified. There are also many details we have chosen not to share from his exposed information. However, it is not our job to pry into people’s private lives nor our intention to expose them. About 10 years ago, EncryptHub fled his hometown in Ukraine due to an unknown incident, relocating to a new city, likely along the coast near Romania. There, he kept a low profile, probably working while self-studying co...
First seen: 2025-04-08 04:23
Last seen: 2025-04-08 13:24