Rhadamanthys

First seen
2022-10-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-07-22 03:48:47
Profile updated
2026-07-07 13:13:54

Targeted industries: technology-and-telecommunications professional-services retail-and-hospitality

Context

According to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines. At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.

Detection coverage

  • 4 YARA rules

Used by threat actors

Detection rules

  • CAPE_Rhadamanthys (yara-rule)
  • CAPE_Rhadamanthys_1 (yara-rule)
  • CAPE_Rhadamanthysloader (yara-rule)
  • MALPEDIA_Win_Rhadamanthys_Auto (yara-rule)

Reports & references

  • recordedfuture.com — The Travels Of Markopolo Self Proclaimed Meeting Software Vortax Spreads Infostealers (report)
  • research.checkpoint.com — Stargazers Ghost Network (report)
  • Trend Micro — Deep Dive Into Water Gamayun (report)
  • blog.google — Ukraine Remains Russias Biggest Cyber Focus In 2023 (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • research.checkpoint.com — Iranian Mois Actors The Cyber Crime Connection (report)
  • Cisco Talos — Highlighting Ta866 Asylum Ambuscade (report)
  • Broadcom/Symantec — Malware Ai Llm (report)
  • esentire.com — Esentire Threat Intelligence Malware Analysis Resident Campaign (report)
  • elastic.co — Deobfuscating Alcatraz (report)
  • x.com — 1900460479778030013 (report)
  • secureworks.com — The Growing Threat From Infostealers (report)
  • research.checkpoint.com — From Hidden Bee To Rhadamanthys The Evolution Of Custom Executable Formats (report)
  • elastic.co — Ghostpulse Haunts Victims Using Defense Evasion Bag O Tricks (report)
  • accenture.com — Information Stealer Malware On Dark Web (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rhadamanthys (report)
  • zscaler.com — Technical Analysis Rhadamanthys Obfuscation Techniques (report)
  • asec.ahnlab.com — 89551 (report)

External references