Decrypting the Inner DNS Workings of EncryptHub
Rising cybercriminal entity EncryptHub seems to have unknowingly exposed elements of its malicious enterprise. An Outpost24 investigation unveiled new aspects of the group’s infrastructure, tools, and behavioral patterns.
The security researchers were able to take a peek into the threat actors’ stealer logs, malware executables, PowerShell scripts, and Telegram bot configurations. These errors shed light on the group’s operations, including their attack chain and methodologies.1
Outpost24 identified 20 indicators of compromise (IoCs) that WhoisXML API expanded through a DNS deep dive.