🇷🇺

Larva-208

APT Group 23 zero-day CVEs

Also Known As 1 names

EncryptHub

Target Countries 2

Countries highlighted in red

Turkey United States

Details

Origin 🇷🇺 RU
Last Updated 05 Jan 2026

Malware Families 2

ps1.silent_prism
ps1.dark_wisp

MITRE ATT&CK 30

T1003 - OS Credential Dumping T1005 - Data from Local System T1021 - Remote Services T1036 - Masquerading T1053 - Scheduled Task/Job T1059 - Command and Scripting Interpreter T1059.001 - PowerShell T1068 - Exploitation for Privilege Escalation T1071.001 - Web Protocols T1078 - Valid Accounts T1082 - System Information Discovery T1090 - Proxy T1105 - Ingress Tool Transfer T1134 - Access Token Manipulation T1140 - Deobfuscate/Decode Files or Information T1195.002 - Compromise Software Supply Chain T1203 - Exploitation for Client Execution T1204.002 - Malicious File T1218 - Signed Binary Proxy Execution T1490 - Inhibit System Recovery T1496 - Resource Hijacking T1498 - Network Denial of Service T1547 - Boot or Logon Autostart Execution T1548.002 - Bypass User Account Control T1553 - Subvert Trust Controls T1555 - Credentials from Password Stores T1566 - Phishing T1566.002 - Spearphishing Link T1584.002 - DNS Server T1587.001 - Malware