Skip to main content

Threats Tagged 'rhadamanthys'

View all threats tagged with 'rhadamanthys'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: rhadamanthys

Threats Tagged 'rhadamanthys'

Click on any threat for detailed analysis and mitigation recommendations

Analysis of over 400 AI-enabled malware samples shows that most remain confined to research and sandbox environments, with only a small fraction observed on protected endpoints across three countries. These samples span five malware families including FunkSec ransomware and Oyster backdoor. Existing behavioral detection, cloud sandboxing, and endpoint analytics successfully detect and block all observed samples. The AI component primarily accelerates malware development rather than enabling evasion of defenses. Distribution patterns are opportunistic rather than targeted.

Join the discussion

A multinational law enforcement operation called Operation Endgame has successfully disrupted SocGholish, a malware framework operated by threat actor TA569 since 2017. The operation took down 106 servers and domains and remediated nearly 15,000 compromised WordPress websites. SocGholish uses fake browser update prompts on compromised websites to trick victims into downloading malicious JScript payloads, providing initial access to corporate networks for ransomware deployment and data breaches. Analysis revealed that 55% of Infoblox cloud customers were exposed to SocGholish in 2026, demonstrating widespread impact across multiple industries including government, education, and healthcare. The framework employs domain shadowing techniques and operates through a four-stage attack chain involving traffic acquisition, filtering, fake update lures, and on-device implant execution. SocGholish infrastructure has facilitated access for various ransomware families and has been extensively used by the notorious Evi...

Join the discussion
0

Threat actors are exploiting AI agent skill formats as a novel attack vector, using convincingly packaged OpenClaw skills to distribute malicious payloads. The latest campaign employs pure social engineering, with skills containing no malicious code themselves but instead tricking users into downloading Windows binaries. The attack leverages a fake GitHub infrastructure hosting GachiLoader, which delivers Rhadamanthys infostealer through fileless injection. The operation uses two delivery mechanisms: Node.js Single Executable Applications and an Electron dropper, both converging on the same payload. GachiLoader employs sophisticated evasion techniques including anti-VM checks, sandbox detection, and privilege escalation, while using a Polygon blockchain smart contract as its C2 resolver for enhanced persistence and obfuscation.

Join the discussion

Gen Threat Labs has identified Remus, a new 64-bit infostealer attributed to the Lumma Stealer family, emerging after Lumma's takedown and the doxxing of its alleged core members. First campaigns date back to February 2026, with the malware switching from Steam/Telegram dead drop resolvers to EtherHiding and employing new anti-analysis checks. Remus shares multiple characteristics with Lumma including identical string obfuscation techniques, AntiVM checks, direct syscall/sysenter handling, indirect control flow obfuscation, and a unique Application-Bound Encryption bypass. The analysis details test builds labeled Tenzor from September 2025, representing a transitional step between Lumma and Remus. While maintaining Lumma's stealing arsenal for browser passwords, cookies, and cryptocurrency, Remus introduces blockchain-based C2 resolution via EtherHiding, additional anti-sandbox checks targeting analysis tool DLLs, and enhanced device fingerprinting capabilities.

Join the discussion

Iranian intelligence services are increasingly engaging with the cyber crime ecosystem, leveraging criminal tools, services, and operational models to support state objectives. This trend is particularly evident among actors linked to the Ministry of Intelligence and Security (MOIS), such as Void Manticore and MuddyWater. These actors are not merely imitating criminal behavior but actively associating with the cyber criminal ecosystem, using its infrastructure, malware, and affiliate-style relationships. This approach enhances their operational capabilities, complicates attribution, and contributes to confusion around Iranian threat activity. Examples include the use of ransomware branding, commercial infostealers, and overlaps with criminal malware clusters. This shift from imitation to active engagement with cyber crime offers both improved deniability and expanded technical capabilities for Iranian actors.

Join the discussion

A new malware distribution campaign utilizing compromised YouTube accounts to spread infostealers has been identified. The campaign employs GachiLoader, a heavily obfuscated Node.js loader, to deploy the Rhadamanthys infostealer. GachiLoader implements anti-analysis techniques and uses a novel PE injection method called Vectored Overloading. To aid analysis, researchers developed an open-source Node.js tracer tool. The campaign has affected over 100 videos with 220,000 views across 39 compromised accounts since December 2024. The malware evades detection, elevates privileges, and disables Windows Defender before retrieving its payload.

Join the discussion

Matanbuchus 3.0 is a sophisticated C++ malware downloader offered as Malware-as-a-Service since 2020, designed to deliver additional malicious payloads including ransomware and remote access trojans like Rhadamanthys and NetSupport RAT. It employs advanced obfuscation techniques such as junk code insertion, encrypted strings, and API hashing to evade detection. The malware features anti-analysis mechanisms including an expiration date and persistence via scheduled tasks. It communicates with its command and control servers using encrypted Protocol Buffers over HTTP(S), supporting a wide range of commands for payload execution, data collection, and system manipulation. While no known exploits are currently reported in the wild, its modular design and use in ransomware campaigns make it a medium-severity threat. European organizations are at risk due to the malware’s capability to facilitate ransomware attacks and backdoor access, potentially leading to data breaches and operational disruption. Mitigation requires targeted detection of its persistence mechanisms, network traffic analysis for encrypted C2 communications, and blocking associated domains and URLs. Countries with high technology adoption and ransomware targeting history, such as Germany, France, the UK, Italy, and the Netherlands, are most likely to be affected.

Join the discussion

A multi-stage malware execution chain originating from a ClickFix lure has been discovered, leading to the delivery of infostealing malware like LummaC2 and Rhadamanthys. The campaign utilizes steganography to hide malicious code within PNG images. Two distinct ClickFix lures were observed: a standard 'Human Verification' and a convincing fake Windows Update screen. The execution chain involves mshta.exe, PowerShell, and .NET assemblies, ultimately extracting and injecting shellcode into target processes. The steganographic technique encodes malicious data directly into image pixel data, using specific color channels for payload reconstruction and decryption in memory. This sophisticated approach helps evade signature-based detection and complicates analysis.

Join the discussion

The October 2025 Infostealer Trend Report highlights the ongoing and evolving threat posed by Infostealer malware families such as Rhadamanthys, ACRStealer, and LummaC2. Attackers have shifted distribution tactics, increasingly leveraging legitimate websites to evade detection and search engine restrictions, a technique known as SEO poisoning. A notable development is the mass distribution of a new Loader malware employing DLL sideloading to execute malicious payloads stealthily. The report also details changes in LummaC2 distribution patterns and the use of sophisticated disguise and phishing techniques to target companies. These Infostealers aim to exfiltrate sensitive information, posing risks to confidentiality and potentially enabling further attacks. The threat does not require known exploits or zero-day vulnerabilities but relies on social engineering and advanced evasion methods. European organizations are at risk due to the widespread use of affected malware and the targeting of companies via phishing. Mitigation requires proactive detection of DLL sideloading, monitoring for SEO poisoning campaigns, and enhanced phishing defenses.

Join the discussion

Check Point Research uncovered a sophisticated malware distribution campaign operating on YouTube, dubbed the YouTube Ghost Network. This network utilizes over 3,000 malicious videos to spread malware, primarily targeting users seeking game cheats and pirated software. The operation involves compromised accounts with specific roles: video uploaders, community posters, and interaction simulators. The network has been active since 2021, with a significant increase in activity in 2025. It mainly distributes infostealer malware, with Lumma and Rhadamanthys being prevalent. The campaign employs various tactics to evade detection, including password-protected archives and frequent updates to payloads and C2 infrastructure. This research highlights the evolving nature of malware distribution methods and the need for enhanced cybersecurity measures.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Tag: rhadamanthys
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses