Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CopyRh(ight)adamantys Campaign: Rhadamantys Exploits Intellectual Property Infringement Baits

0
Medium
Published: Wed Nov 06 2024 (11/06/2024, 18:33:53 UTC)
Source: AlienVault OTX General

Description

The CopyRh(ight)adamantys campaign is a large-scale phishing operation distributing the latest Rhadamanthys stealer malware (version 0. 7). It uses copyright infringement-themed bait emails impersonating companies mainly in the Entertainment/Media and Technology/Software sectors. The campaign employs automation and possibly AI tools to tailor and distribute lures globally. Rhadamanthys stealer targets sensitive information by leveraging various techniques including OCR-based text recognition and credential theft. Although the malware claims AI-powered capabilities, it primarily uses traditional machine learning OCR methods. The campaign is financially motivated, not linked to nation-state actors, and poses a medium severity threat. European organizations in targeted sectors face risks of data theft and credential compromise. Mitigation requires targeted phishing awareness, enhanced email filtering, endpoint detection, and credential hygiene. Countries with strong media and tech industries and high phishing exposure are most at risk.

AI-Powered Analysis

AILast updated: 12/10/2025, 09:36:59 UTC

Technical Analysis

The CopyRh(ight)adamantys campaign is a sophisticated phishing operation deploying Rhadamanthys stealer version 0.7, a malware designed to exfiltrate sensitive data from compromised systems. The campaign uses copyright infringement claims as social engineering lures, impersonating numerous companies primarily in the Entertainment/Media and Technology/Software sectors. This thematic bait aims to exploit recipients' concern over intellectual property violations to increase click rates. The campaign's scale and sophistication suggest automation and possibly AI-assisted generation and distribution of phishing emails, enabling tailored targeting of specific entities globally. Rhadamanthys stealer includes features such as credential theft, system reconnaissance, process injection, and data exfiltration using various techniques mapped to MITRE ATT&CK tactics (e.g., T1082, T1071, T1566). Notably, the malware claims AI-powered text recognition for extracting data from images or documents, but analysis shows it relies on older OCR machine learning methods. The campaign is financially motivated cybercrime rather than espionage, focusing on stealing credentials and sensitive data for profit. No known exploits in the wild beyond phishing delivery are reported. The campaign's use of copyright infringement baits and targeting of media and software sectors increases its effectiveness against organizations sensitive to IP issues. The campaign's medium severity reflects its potential for data theft and credential compromise but requires user interaction and phishing success for infection.

Potential Impact

European organizations in the Entertainment/Media and Technology/Software sectors are at heightened risk due to the campaign's targeted lures. Successful phishing can lead to credential theft, unauthorized access to corporate networks, intellectual property leakage, and potential downstream ransomware or fraud attacks. The theft of sensitive data can damage corporate reputation, lead to regulatory penalties under GDPR for data breaches, and cause financial losses. The campaign's automation and AI-assisted phishing increase the volume and sophistication of attacks, making detection harder and increasing the likelihood of successful compromises. Organizations with remote or hybrid workforces may face increased exposure due to reliance on email communications. The campaign's focus on copyright infringement baits may also cause distraction and increased susceptibility among legal and IP departments. Overall, the campaign threatens confidentiality and integrity of corporate data and can disrupt business operations if credentials are abused.

Mitigation Recommendations

1. Implement advanced email filtering solutions capable of detecting phishing emails with intellectual property infringement themes and AI-generated content. 2. Conduct targeted phishing awareness training emphasizing the risks of copyright infringement claims and suspicious attachments or links. 3. Deploy endpoint detection and response (EDR) tools to identify Rhadamanthys stealer behaviors such as credential dumping, process injection, and data exfiltration. 4. Enforce multi-factor authentication (MFA) across all critical systems to reduce impact of credential theft. 5. Regularly audit and monitor user accounts for unusual access patterns or privilege escalations. 6. Use network segmentation to limit lateral movement if a system is compromised. 7. Maintain up-to-date backups and incident response plans tailored to malware infections. 8. Employ OCR and AI content analysis tools to detect suspicious documents or images in emails. 9. Collaborate with threat intelligence providers to stay updated on campaign indicators and tactics. 10. Restrict execution of unauthorized scripts or binaries that may be used by the stealer.

Need more detailed analysis?Get Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://research.checkpoint.com/2024/massive-phishing-campaign-deploys-latest-rhadamanthys-version/"]
Adversary
null
Pulse Id
672bb6914143e196a427520e
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash0f554ec32dce7a85e58bc6732f74902f
hash1a0697d9fd550f5d212cbf6a865064e9
hash26b6cdc556f3801f3d947a15a28032ba
hash302f20d286832b4680001bec57079cc0
hash3fb20e307b9e77310b70d26f626b0247
hash4346b52cff0853f3a08f4e98c71fec1a
hash543b69f96203ebf17cbb6fb6b4b424f0
hash573baaf10e2cd69e7749e8d65c5adabf
hash584e4161617ca3afac3cbdf52efd2877
hash6d1237dee6c827181c572126e6729d5a
hash78509f0c765b344f2bca1fc2701c0980
hashc2a40f79df1fb7a961f1c1217e01438f
hashc43f5fc6874d3e5e92a9f6bb7f0f2e89
hashde1ad6ab02075747b8715740ea1b6a69
hash0ab247f8f8e1deddd981f132b68647fc404fc0a8
hash0b1be2f5d9ba43075a0f4856e6bdea670742a096
hash244fe1bd3221af1757fcdc4fc7ac74041824a374
hash2879aae0d563b38b564c0c8905788fcf8c3e4b70
hash462c8ef17de04f84ffed95875fcbcb7a8d334228
hash4a1e2e78361f170737e699c086fcc9d3f4bf3baf
hash5010602fc1ea9b5a51661180a255a262482ed8ef
hash5dee5831f32c3ca056af00e98434adafc86e3c6b
hash609629f1c48a3f0c0d2635c45a8714c08fbdc76f
hash6f75df828a3fa43a62ba0f6a70ed356bc8807fe1
hash9970691793ac409fd9147618126779a2be0c191b
hashbd2db94c345172e1278c723f97497a947ac99d52
hashc43504e6707cf1403a671fafdfe6de2dc8c73464
hashfe107e3a785df12c83a8ffaee7d3496c0c4c47e0
hash00086cf4f35b6fb7f897cfa2f0d5ad9876aa9819cdc87416c798005ce901d3a1
hash00fc4b8a4c65c06766608f3ef3f92385c8e147f5991dabe290e33dd14b39ad44
hash05e02f0f9b8625fe3959ae1219f31b0167d787fefc0a9d152edf6524d6859590
hash0a3dfe260dd7b038ddb8911689c899541391c188aff966261e7bd9d0280d153d
hash0ad65fd0897a6547f6febf398708ab2d423a8f8834b53136219cb490ec3ebd13
hash0b9bd95d815af9ea4a59840ef6fcdc7ccfd0e239c40974334cb4cfb41df530db
hash0de8d2d3217cebd37a2fe488713d1c288ae5a63d3d3b2a3495e2e636ba6a1f89
hash10eafd75429ffadee2384acd37b0d4e7ca26b83666e6786f2acaf1b1c29c3f17
hash11ba24d023b544e28c37b6cb8afe27d06638175d7f56c2e4d4ff97bf7bd813b6
hash12b7390835f30c1bcdeddd258e49684c98133cee4a6a2ccab869785567deae4f
hash13872271ee511aa83f3f27d5db248516652b10a079ad01f78ed734cd2a87ec77
hash18273fa35c54332d8763cb17a5ae92de5636f3a05c507ce18d9d6a77c3139deb
hash1a2399ecc38f3288206c75b55762d125d3d75254062a2c0d85c86e7f896736ac
hash219a6387d91c4b2c8e91c8613192af950bd9c790114a238eb0e1e7c878f6e728
hash258ffcc13dbe110bcce21b91f7f075995719791fdd3c9f55ea5934984fa4373d
hash2625d99af56c79de32f9fba2332f63eb9c88707e9ea83985bce5df9022ced99a
hash2a276ca5b2e095cdac7b24e58b3f7a67cee7db2fb5c1568e4775909265c7e914
hash2aa58fa8d71bd2b4fd1ffac16a6461191bbf6f4b2c97455ae52800cce929a0f2
hash2be6ad454fa9e87f78dea80d2855f1c14df81a881093a1a0d57f348377f477a8
hash2cbc1e8a4cb5d18a867666adbd3417bc88d48a74ae6500593959aec1a1c92d2d
hash2e0c99758432a3759b5af6f190ec5cb72a5a84c977d8883dcf041c4de003f3d3
hash324dfc7bb75f27e6fba8d67dea67a63525efbe947bf8e29ef39980c6efc1c3f6
hash342a5c7df2bdd040570f4b83c74366d4c96a90d6418149d432cb5e8577f2f6b1
hash3448005600ccb0ae52443a4c227a657de9cd767b389e9a1ed75ef074709981bd
hash3648e89e7449ea433a8b3ef0e5b605b5dc4157048c03b20dedc5e3b920fa8552
hash3737501bbd4abd0844da016c0263399e3c670ae52952b30ca46c6c96cf4e318d
hash37438095a5e7be0ce12997dc23d1ff117912989d2f24beab95284f9380f65834
hash3ca87045da78292a6bba017138ff9ee42b4e626b64d0fee6d86a16cc3258c8c3
hash3d010e3fce1b2c9ab5b8cc125be812e63b661ddcbde40509a49118c2330ef9d0
hash3de252c9023bc8920d77570acdfe21813532727af3f91d59af35fa8abcd3700f
hash3ecf2838b2e07e6d329d45cde7d0162ba47fea4b94bacb24838358314daed756
hash415ee9b12002f17ca4f36bef794fdb19884e22980e21bf8a15043258624c439b
hash416f3fa48b75ab168e3373dae77cab7f4702de5158835d23a02629e8c1d20156
hash41a3edb3a8e8d5cf093cbd02791911f6ee26df39a377fceb6b101d66a7b7aff2
hash44f3936ee158d2846664bf5cd795fd90a99441186b20b90ff241ba1b38a6a3e9
hash48aaa2dec95537cdf9fc471dbcbb4ff726be4a0647dbdf6300fa61858c2b0099
hash4b33219c5cadb4d741044874f6f0184d45f43891d28ad5b489716d4da21310fd
hash4bbe0f6b5488a51295b15d8144d0a1c9b41bb86384299b88ea48e88c76704f52
hash4cbcfa2a8d56976eff1e8ac0ef4d7703d0b802f227975a0cc36f3dcd3a90e73e
hash4fd469d08c051d6997f0471d91ccf96c173d27c8cff5bd70c3f2c5008faa786f
hash5418e42706bca4712ff2a3db67853eb42a2310660c51cff2f9020586cffedeb3
hash5cec33e8f47855da3c4ce1f3953d750275864714b16e08a94605bc3889867caf
hash6012386eab453f4fb1cfb88fb5b05ba9ec71a838029ea51bcff4c0b5a2fbfad2
hash6044e08402d1abd52991f5c6a4749ba6aa29a0587ff196edf60b38862392e855
hash623bb3f1f476c37afc309d6c0ab89e216aaedc03b8a7ec1aaec5fb5085d78a97
hash633b0fe4f3d2bfb18d4ad648ff223fe6763397daa033e9c5d79f2cae89a6c3b2
hash69573694d16b7ccadfa208ff976bfe1b3e36837aba3e5dc4dfc80e66341ef61e
hash6de4f65b1d738d84f8e825613092bbd360194195fe8a1c986e12a9bb704217c1
hash741dfdae8948f3e430a5b7b66c8fb4b8a750695b67a84a12abc0b6089e8fba31
hash751f149665f87dd20cc8dff743f28e5da1ff2a5f04874d4b8569b9afceeedfec
hash78200cd816acbd39b6664c6582e06500f6d46085b62b49d2f914bea5a004197a
hash783c7f4bf23072343f6247ee14e54e4af0b147553ad1ef42b4e7fb44386d667c
hash7990765022c4400a45f996046971b9e6b69cca5b06f8d2adb61bc267fd362197
hash7d7a3e254b7968400a301d83fcd44a69f655386b9b95998a36113cfb2e542720
hash7dc07b8aa268485e40ab78bfbb03a367d80ebd7b2c6c74961dc6842cae7086e1
hash7e270a80cd0f04f245309e8c75cfc2cb46dc075ba01a00b30f66cb8b5deaaf3f
hash7f99e506c17676b98dcc08e6a19f100ef933cde3e0423c6d4072f6802a9196bb
hash865a4f2583679f7a40357b61301d75567cf516a5b8295dc8155e6d4aa2ce244a
hash878917b6a8d241031fc330eff771f416a9fffaecab42c39d57e58ac2d8f38f11
hash8d0b1174cbda6b102bb98c91ba123e9f404b9fad23b49a4e29f3cfd8d20a577a
hash90c7688e0dc23ba4530bac1d567bad920c4ef1c06cbf4b2d867eeb363271eefe
hash9102e564c3262b2c291e8ca3d67f8a55c06650aa86f617c919916f6053c03c9b
hash9327aa03760431b6d86eeb2f1a3efc36aa443b842b5116fbbe0f2a7794c4e70e
hash970e199e40511e90d6dd5d6f3c9f3701215fd881b1273fe2617bd44444b0bee9
hash97286b6f3a6535ff1172ef65172e6967e3670c6b14a3313c3bf0d6c171b1fc85
hash98e28d3423f5d414effe3c0ed6fd0f1c8154942e5e127ecee5f051e1196ffc75
hash99c0bebdc8cb7b0948000a601f510fc70487f9da532be199b8641512a2db9839
hash9a249dfdc2c16700bc5add2455f2ed00e47a2610b7779cc33e40aac576a2a74d
hash9abf9fb94e2529d8819a3873f2025bdd90d14e75fe4af81e489f6d0560809f9c
hash9bdf49b27fd4d80ef087f63e0bfa0a0822686814863eca09ac506404ad76dfda
hash9d10835f7717c89d17886b7e59cc2dfc9133bfaa044bad5f070e1c8e1212e257
hash9ef9c88cef51ee0fb77ea9a78dbe60651603ef807ddb6c44d5bda95cc9026527
hasha03d2956ff8d0ae4d96c9e6cced79b335b70eef10feb0f7202609cb8652179f6
hasha064bbc4b58642ab4d7118abc55fb81db6584cbc633800ad14048e8370a95ef2
hasha15d0aedc8b4e54a170b6ecc3d9a06835cc499f07b05c6ca261081ace505debf
hasha72083974e886856b7d985bdc79888234c8cd9012ed39b2566851fb0d86cca50
hasha87032195e38892b351641e08c81b92a1ea888c3c74a0c7464160e86613c4476
hasha8729621ca4310e8e1a7ad3e1426708f1e1954a16af420cd3ce46c501e9692ab
hasha905226a2486ccc158d44cf4c1728e103472825fb189e05c17d998b9f5534d63
hasha9896a8f96407a5eedda08a63dd40967f0fe0b3926e7002b6e1abc11f6ab81cc
hashaa04c9307a9087455d21dfac02d7f322ab337cd5978f9161285a9c79379efecc
hashaeba4ece8c4bf51d9761e49fad983967e76c705a06999c556c099f39853f737c
hashb1ac4ad92045e935c132214015188d27ec4382f930d0152dfb303695b708b38d
hashb2588061ba5ee9948bbccd320b40c6d7b8d6a693d181f3bce61e5e267f53aa7e
hashb36205464ead176a473ab43ea7b5e0c2b8749b3eb9549d65609be2337dce25db
hashb529c6df6164ff8badf30f942220a3126f99e3fc2c2ea1494aa3e305b3b53c1f
hashb936853a0c50a0cd0bc8b33103b55bd88e19c6c28768d990b954c11d714286ca
hashb97dd0279e112e0591b38064f59077102ab188b07a069cb104e66e4756e2570a
hashb9c4c8343ba75081954b2db54940585c6c0c9bb47e053ac1b9229b4fa8fc9293
hashbe9c3feed5f6e81ccd375902c8c92616f77694b6cd14f69896d44dd4b1ea4990
hashbea558e8129fcb647e6f42c8beda4464e109dd3cd546342c0337dbd50616f991
hashc0b319bb19092fe3c193e5139fcdf599502b669143b06c676e81f46ab50fb4ed
hashc5bb808a88f9e729484c05a1bc3097157bbfbd28469e502f2ebc4c6e6135df42
hashc622c0f67eb5d9a90008e5e120065cd5a1a6e25c6e758e8205d377596059b8fe
hashccb539bf17d479d9707ee717d0afb03cd57e9b6f023becf1abf9cdbd88e1b06c
hashcd3040c88a6fd71ed1ce8c2a5d0b13ed8e25e49835932a39891c514ef946dd29
hashce2f00f1d0e71287e746d5a3507547f355297a3e45a7c2cc0322015916a0137c
hashcf9d93951e558ed22815b34446cfa2bd2cf3d1582d8bd97912612f4d4128a64e
hashd00d3adf81bf95ff4994dcbd2ae1305a6ee6b0edfad6eb55b87217f85645651a
hashd0e3f547e3efcc9d9794774a765b9c3950955e7ad752f3e630ebd5ab9425bcdc
hashd285677cba6acf848aa4869df74af959f60ef1bc1271b4032000fcdd44f407f2
hashd452461f3527d674de3e9b680026ceb2b02c56d6d3f7c94da3aab65c05f52c03
hashd57f45096e646837dec51129222fcbe79981c595721164009aec68be09bf5dcf
hashd96ec4b08c08b81ba9075423d5e83bf330de09866066b4bdb459bcbac389a350
hashd97aa65123c26509e3fc1a9963962b7f707a50ddca44a9a12fd03e654ab5aa66
hashdbb4f7e6354621c316fbba7e7a15f59cf229684e16ab6d21027f310beecaf49b
hashdbdeede6f39936305c4c5bd8e4f7bfccb0b823c025130e7f8fa285e80383be0f
hashdc3d72f72247141efeba3c2ffd498025f68e0c4b34c9a4dc2686ffec09b6d401
hashde933f7b47707f4bf8d5a4aaef8b31f5059d3b8f465bcaae3e22438466e8390b
hashe6315b24e0311758da1c25daa5f2724da4f534ed7ed644cbf43f3cc64c4676a7
hashe8aa9a061c6ea803faaf4c8d7a80c6886b4ee73d9a89a9dc6e87e3fecf7a6851
hashe9a18755312011e30081e7ce0fcc1db3e3aec3b9f3ed3a776dd38498830a2738
hasheb4e39d44ad016b8d6d1dc8dc25a9ea3d3e18df87516922fdbd995de15b68f54
hashebd167ca477af620065548a9e55567682b0750625b3e078fc4498dd5adeabdc6
hashf2429f4bd09897653d0ffa41206a14cafa55356d5edc04dc0915c116867f8c27
hashf2536e520d37512d868a418797974a5c11e67742824a5477100b7e3f5b2efbc3
hashf4fcba1c9d7f4ae8e3868f901035ea1e0e9e1122a362a83afd3d111c17a97d7a
hashf7eef906c7dc1ce2ffe586d4b7f316a5f5c6761b5cdbf22d892fbc87a5ee2f6f
hashfcb00beaa88f7827999856ba12302086cadbc1252261d64379172f2927a6760e
hashfd9fbfa809450415e8d0d79199ec8686cb7071d6e13a5b76f0ce1b03a2a61302
hashfe55c1d263e0ea356d86afd8b2b1cedff570568e45b8a3810e05ea482b8a9329
hashfefba5ce20c71a71cfe35dd8ff06c514bf6ffde60356babf4f4bba66dd904b78
hashffb264a19af7c8a8dd5357b62c45fcd3063ca946aa2710740c4e8b21f8e697d9

Domain

ValueDescriptionCopy
domainwww.blockplate.com

Threat ID: 69393eea681246c13de6475c

Added to database: 12/10/2025, 9:35:38 AM

Last enriched: 12/10/2025, 9:36:59 AM

Last updated: 12/10/2025, 12:00:04 PM

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats