Researchers from KrakenLabs have exposed the operations chain of malware threat actor EncryptHub after the latter suffered security lapses. EncryptHub had compromised over 600 entities, using a multi-stage process involving trojanized applications and sophisticated scripts to extract sensitive victim data. KrakenLabs also found that EncryptHub uses a third-party “pay-per-install” broker to spread its malware and is developing a control interface, called EncryptRAT, to manage attacks more efficiently.

Week in review: How QR code attacks work and how to protect yourself, 10 must-reads for CISOs
Cybersecurity news over the past week highlighted the risks of increasing QR code attacks and social media scams. AI-powered simulations may enhance cybersecurity teams’ skills