Malware

Banking

Data Stealer

Cybercrime

Financial Fraud

Rhadamanthys

Rhadamanthys

Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines. This malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.

Known Variants

Known Variants

Rhadamanthys infostealer with modular capabilities for credentials and session data theft.

Rhadamanthys infostealer with modular capabilities for credentials and session data theft.

Mitigation Strategies

Mitigation Strategies

Protect sensitive data by employing endpoint protection tools, using behavior-based detection systems, and implementing browser security hardening. Regularly review network activity for unusual patterns indicative of data exfiltration attempts.

Targeted Industries or Sectors

Targeted Industries or Sectors

Targets financial services, e-commerce, and retail, focusing on stealing customer data and credentials.

Targets financial services, e-commerce, and retail, focusing on stealing customer data and credentials.

Associated Threat Actors

Associated Threat Actors

Primarily linked to cybercriminals focused on monetizing stolen credentials through fraud or resale

Primarily linked to cybercriminals focused on monetizing stolen credentials through fraud or resale

References