Larva-208 (EncryptHub) is a financially motivated group using phishing and MFA bypass to deploy ransomware.
Analyst brief
Larva-208 (EncryptHub) is a financially motivated threat actor that uses sophisticated phishing campaigns for credential harvesting and ransomware deployment. They have targeted over 618 organizations since June 2024, focusing on gaining access to corporate networks. Key TTPs include Open URL Redirection, fake login pages, social engineering, and MFA bypass; the group is linked to Larva-148 for domain acquisition and attack management. Defenders should focus on detecting phishing emails, monitoring for suspicious URL redirects, and implementing additional authentication controls to counter MFA bypass attempts.
Larva-208
EncryptHub
unknown
LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multiple tactics, including Open URL Redirection, fake login pages, and social engineering, to bypass MFA and gain access to corporate networks. LARVA-208 has compromised over 618 organizations since June 2024, often deploying ransomware payloads. The threat actor is linked to LARVA-148, a threat actor managing domain acquisitions and attacks.