Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    New Philips Hue update improves battery status accuracy

    GameSir’s GameHub is bringing Steam (PC) games to Mac

    Asus and Acer hit with laptop and PC sales ban amid Nokia HEVC patent dispute in Germany

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025
    • Crypto

      Binance Denies Sanctions Breach Claims After $1 Billion Iran-Linked USDT Transactions Reported

      February 16, 2026

      Ray Dalio Says the World Order Has Broken Down: What Does It Mean for Crypto?

      February 16, 2026

      Cardano Whales are Trying to Rescue ADA Price

      February 16, 2026

      MYX Finance Lost 70% In a Week: What Triggered the Sharp Sell-Off?

      February 16, 2026

      What Really Happened Between Binance and FTX? CZ Finally Tells His Side

      February 16, 2026
    • Technology

      New Philips Hue update improves battery status accuracy

      February 16, 2026

      GameSir’s GameHub is bringing Steam (PC) games to Mac

      February 16, 2026

      Asus and Acer hit with laptop and PC sales ban amid Nokia HEVC patent dispute in Germany

      February 16, 2026

      Kingdom Come: Deliverance gets a next-gen 60 FPS update as its Royal Edition with all DLCs drops to $7.99 on the PlayStation Store

      February 16, 2026

      Eufy launches motion detector with smart feature in new market

      February 16, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher
    Technology

    EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher

    TechAiVerseBy TechAiVerseApril 8, 2025No Comments4 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher

    EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research.

    The reported vulnerabilities are CVE-2025-24061 (Mark of the Web bypass) and CVE-2025-24071 (File Explorer spoofing), which Microsoft addressed during the March 2025 Patch Tuesday updates, acknowledging the reporter as ‘SkorikARI with SkorikARI .’

    Bug reporter
    Source: Microsoft

    A new report by Outpost24 researchers has now linked the EncryptHub threat actor with SkorikARI after the threat actor allegedly infected himself and exposed their credentials.

    This exposure allowed the researchers to link the threat actor to various online accounts and expose the profile of a person who vacillates between being a cybersecurity researcher and a cybercriminal.

    One of the exposed accounts is SkorikARI, which the hacker used to disclose the two mentioned zero-day vulnerabilities to Microsoft, contributing to Windows security.

    Hector Garcia, Security Analyst at Outpost24, told BleepingComputer that the link of SkorikARI to EncryptHub is based on multiple pieces of evidence, making up for a high-confidence assessment.

    “The hardest evidence was from the fact that the password files EncrypHub exfiltrated from his own system had accounts linked to both EncryptHub, like credentials to EncryptRAT, which was still in development, or his account on xss.is, and to SkorikARI, like accesses to freelance sites or his own Gmail account,” explained Garcia.

    “There was also a login to hxxps:// github[.]com/SkorikJR, which was mentioned in July’s Fortinet Article about Fickle Stealer, bringing it all together.”

    “Another huge confirmation of the link between the two were the conversations with ChatGPT, where activity related both to EncryptHub and to SkorikARI can be observed.”

    EncryptHub’s foray into zero-days is not new, with the threat actor or one of the members attempting to sell zero-days to other cybercriminals on hacking forums.

    EncryptHub attempting to sell a zero-day on underground forums
    Source: BleepingComputer

    Outpost24 delved into EncryptHub’s journey, stating that the hacker repeatedly shifts between freelance development work and cybercrime activity.

    Despite his apparent IT expertise, the hacker reportedly fell victim to bad opsec practices that allowed his personal information to be exposed.

    This includes the hacker’s use of ChatGPT for developing malware and phishing sites, integrating third-party code, and researching vulnerabilities.

    The threat actor also had a deeper, personal engagement with OpenAI’s LLM chatbot, in one case describing his accomplishments and asking the AI to categorize him as a cool hacker or malicious researcher.

    Based on the provided inputs, ChatGPT assessed him as 40% black hat, 30% grey hat, 20% white hat, and 10% uncertain, reflecting a morally and practically conflicted individual.

    The same conflict is reflected in his future planning on ChatGPT, where the hacker asks for the chatbot’s help in organizing a massive but “harmless” campaign impacting tens of thousands of computers for publicity.

    Exposed ChatGPT discussion
    Source: Outlook24

    Who is EncryptHub

    EncryptHub is a threat actor that is believed to be loosely affiliated with ransomware gangs, such as RansomHub and the BlackSuit operations.

    However, more recently, the threat actors have made a name for themselves with various social engineering campaigns, phishing attacks, and creating a custom PowerShell-based infostealer named Fickle Stealer.

    The threat actor is also known for conducting social engineering campaigns where they create social media profiles and websites for fictitious applications.

    In one example, researchers found that the threat actor created an X account and website for a project management application called GartoriSpace.

    Fake GartoriSpace website
    Source: BleepingComputer

    This site was promoted through private messages on social media platforms that would provide a code required to download the software. When downloading the software, Windows devices would receive a PPKG file [VirusTotal] that installed Fickle Stealer, and Mac devices would receive the AMOS information-stealer [VirusTotal].

    EncryptHub has also been linked to Windows zero-day attacks exploiting a Microsoft Management Console vulnerability tracked as CVE-2025-26633. The flaw was fixed in March but was attributed to Trend Micro rather than the threat actor.

    Overall, the threat actors’ campaigns appear to be working for them as a report by Prodaft says the threat actors have compromised over six hundred organizations.


    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleMicrosoft delays WSUS driver sync deprecation indefinitely
    Next Article How the Pentagon is adapting to China’s technological rise
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    New Philips Hue update improves battery status accuracy

    February 16, 2026

    GameSir’s GameHub is bringing Steam (PC) games to Mac

    February 16, 2026

    Asus and Acer hit with laptop and PC sales ban amid Nokia HEVC patent dispute in Germany

    February 16, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025680 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025261 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025155 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025112 Views
    Don't Miss
    Technology February 16, 2026

    New Philips Hue update improves battery status accuracy

    New Philips Hue update improves battery status accuracy – NotebookCheck.net News ⓘ Philips HueSome Philips…

    GameSir’s GameHub is bringing Steam (PC) games to Mac

    Asus and Acer hit with laptop and PC sales ban amid Nokia HEVC patent dispute in Germany

    Kingdom Come: Deliverance gets a next-gen 60 FPS update as its Royal Edition with all DLCs drops to $7.99 on the PlayStation Store

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    New Philips Hue update improves battery status accuracy

    February 16, 20263 Views

    GameSir’s GameHub is bringing Steam (PC) games to Mac

    February 16, 20262 Views

    Asus and Acer hit with laptop and PC sales ban amid Nokia HEVC patent dispute in Germany

    February 16, 20263 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.