It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.
Rhadamanthys
Rhadamanthys is a Windows information-stealing malware family written in C++ that has been active since late 2022 and is commonly offered through malware-as-a-service subscription models.
Profile source: Mallory opens in a new tabRhadamanthys
Family profile
Rhadamanthys is a Windows information-stealing malware family written in C++ that has been active since late 2022 and is commonly offered through malware-as-a-service subscription models. It is used to collect and exfiltrate sensitive data from infected systems, including browser credentials and cookies, system information, cryptocurrency wallet data, and information from a broad range of desktop applications such as password managers, VPN clients, FTP clients, messaging platforms, email clients, gaming platforms, and file-transfer tools. Reported targeting includes cryptocurrency-focused victims, business users, and enterprise environments where follow-on compromise can enable broader intrusion activity.
Rhadamanthys is distributed through multiple criminal delivery channels, including phishing and malspam, malicious online advertisements, fake software installers and updates, cracked or pirated software, drive-by and loader-based infection chains, and deceptive landing pages that impersonate legitimate software brands. It has also been observed as a final payload delivered by other malware and access services, including Dolphin Loader, GHOSTPULSE, TA866-associated chains, and broader stealer-traffer ecosystems.
Technically, Rhadamanthys commonly uses staged execution and strong defense-evasion tradecraft. Documented samples include packed droppers, in-memory shellcode decryption and execution, callback-based shellcode launch, anti-VM and anti-analysis checks, suppression of error dialogs, mutex masquerading, dynamic API resolution, and user-mode unhooking or inspection of security-related modules. Some observed chains use AutoIt intermediates, DLL execution via rundll32, and process injection to launch or protect the final stealer. The malware communicates with command-and-control infrastructure to transmit stolen data and can receive additional tasking or payloads.
Rhadamanthys has been associated with financially motivated cybercrime operations and has appeared in campaigns linked to malvertising crews, traffer teams, and threat actors such as TA866. It has also been used alongside other commodity stealers and loaders including Lumma, Vidar, StealC, RedLine, SectopRAT, DarkGate, and NetSupport. Its prevalence made it one of the more prominent infostealer services in 2025 before major law-enforcement disruption efforts, including Operation Endgame, targeted infrastructure associated with the malware.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Process Injection
Reported operators
Threat actors
13 named in public reportingRhadamanthys is an information stealer that can be used to collect and exfiltrate a variety of sensitive data from infected systems.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
Deploy advanced endpoint detection and response (EDR) solutions to monitor for and block the execution of known malware families associated with Crazy Evil, such as Rhadamanthys, Stealc, and AMOS.
It also recently added a commercial infostealer - Rhadamanthys - sold on cybercrime forums to its arsenal, according to Check Point.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Tools like Rhadamanthys, a commercial infostealer available on darknet forums, appeared in Handala-linked operations paired with custom wipers in phishing campaigns impersonating software updates from vendors such as F5.
Proofpoint in April, who suspected TA547 (aka "Scully Spider") of deploying an AI-written PowerShell loader for their final payload, Rhadamanthys info-stealer.
EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.
In a number of cases, we observed attempts to use NetSupport RAT to install stealers such as Rhadamanthys and Meduza.
Exploited software
Vulnerabilities linked to Rhadamanthys
1 CVEsMITRE ATT&CK
Rhadamanthys in ATT&CK
79 distinct techniquesTechniques
79 techniquesReporting
Research mentioning Rhadamanthys
ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul
Rhadamanthys3
Infostealers StealC and Amadey Disrupted in Police Crackdown
Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.
Amadey, StealC malware operations disrupted in Operation Endgame action
The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.
Infostealers StealC and Amadey Disrupted in Police Crackdown
Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.
Правоохранители очистили 15 000 сайтов, зараженных SocGholish - Хакер
Напомним, что в прошлом году в рамках операции «Эндшпиль» были отключены более 1000 серверов, связанных с Rhadamanthys, VenomRAT и Elysium.
Operation Endgame Disrupts SocGholish Malware Infrastructure
police shut down over 1,025 servers used by three other malware groups, terminating the core infrastructure of the Rhadamanthys infostealer, the VenomRAT remote control tool, and the Elysium botnet
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
In November, as part of Operation Endgame, law enforcement agencies also took down over 1,000 servers used by the Rhadamanthys, VenomRAT, and Elysium botnet malware operations.
Атаки через украденные учётные данные: kill chain 2024
Rhadamanthys - заменил LummaC2 в некоторых панелях управления после правоприменительных действий