Last seven days
- First activity
- Aug 30, 2026
- Last activity
- Sep 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 21 IP / 6 hostnames
Rhadamanthys is a Windows malware-as-a-service information stealer first advertised on Russian-language cybercrime forums in September 2022 by an operator using the King Crete alias.
Profile source: Mallory opens in a new tabRhadamanthys
Rhadamanthys is a Windows malware-as-a-service information stealer first advertised on Russian-language cybercrime forums in September 2022 by an operator using the King Crete alias. It is a modular, multi-stage malware family with a development lineage that exhibits substantial architectural and code overlap with Hidden Bee. Rhadamanthys is used in broad financially motivated credential- and cryptocurrency-theft campaigns, commonly delivered through phishing, fake software-download sites promoted by malicious advertising, and social-engineering infection chains. It has also appeared as a secondary payload in loader-mediated compromises.
The malware collects host information, screenshots, browser credentials, cookies, browsing data, autofill records, saved payment-card data, browser extensions, and data from cryptocurrency wallet applications and browser wallet extensions. It targets credentials and data associated with password managers, KeePass, FTP and email clients, VPN clients, messaging applications, two-factor-authentication applications, remote-access tools, and other desktop software. Later versions added keylogging, collection from other local user accounts when permitted, file-grabbing capability, and OCR functionality intended to locate BIP39 cryptocurrency wallet recovery phrases in images and documents. Rhadamanthys can also execute attacker-supplied PowerShell, scripts, native payloads, and .NET assemblies.
Rhadamanthys employs custom module formats, encrypted configuration data, staged in-memory loading, process injection, custom virtual filesystem packages, and steganographic delivery of later stages in image or audio files. Its anti-analysis and defense-evasion features include virtual-machine obfuscation based on the Quake 3 VM, sandbox and debugger detection, API resolution obfuscation, NTDLL unhooking, raw and indirect syscalls, ETW and AMSI bypasses, and Heaven's Gate transitions for 64-bit execution from WoW64 contexts. It can establish persistence through host configuration changes and execute additional modules or commands received from command-and-control infrastructure. Rhadamanthys is associated with cybercriminal activity rather than a conclusively identified nation-state operator.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4757b008f984a79a393d6838a0482e71623ed763af65d9fc1ced963caeea64ca 902bea9e4aeeed4e0b5d30a9cbcc6f9f1fc687b79c3fdde8258b94b410d1797a a7c4ea072d7d27716906c0303adb1165253aadb98c6be1672278b7f48514d931 bf258d449b89e60adde308adb9e1204e4b8052894f0cfaf1fb83ea2904de89dc 3c6126417211aacd1bb0ebadcd474747890e8930a4684ccabe448d1390b3c064 78cf8d71ec2451e820a7260f79e1bad47db041c004690668e11c05b1c7d764d3 86169823504bfb77ddf5e199fa2c683db27fcf06bf4f385f114e48e089120986 c391c8763b10b0a558f274e9553624edf70212b4658527fc7af97e0bed249254 d9f8bfbb716f94e359f88cbe21d23f7d48cd7a24cadf71207e5a2eafbb91cf4b Reported operators
In this campaign, WasabiSeed is utilised to drop a number of files, ending with the Rhadamanthys Information Stealer.
Check Point Research is tracking an ongoing, large scale and sophisticated phishing campaign deploying the newest version of the Rhadamanthys stealer (0.7).
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias โmarkopoloโ, an IAB spreading StealC, Rhadamanthys and Atomic
It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
Deploy advanced endpoint detection and response (EDR) solutions to monitor for and block the execution of known malware families associated with Crazy Evil, such as Rhadamanthys, Stealc, and AMOS.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.
Tools like Rhadamanthys, a commercial infostealer available on darknet forums, appeared in Handala-linked operations paired with custom wipers in phishing campaigns impersonating software updates from vendors such as F5.
Proofpoint in April, who suspected TA547 (aka "Scully Spider") of deploying an AI-written PowerShell loader for their final payload, Rhadamanthys info-stealer.
EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.
In a number of cases, we observed attempts to use NetSupport RAT to install stealers such as Rhadamanthys and Meduza.
Exploited software
MITRE ATT&CK
Reporting
A targeted social-engineering campaign compromised a cryptocurrency organization after a Windows employee was lured through a fake Web3 hiring process that began with LinkedIn recruiter outreach and moved through Calendly scheduling to a bogus Google Workspace-style technical assessment. The assessment redirected the victim to install a signed Microsoft ClickOnce application, GapiUpdate.application, which used trusted Windows deployment behavior and Google-themed presentation to appear legitimate. The infection chain deployed NeedleStealer, a Rust-based information stealer, and a Go-based hVNC RAT, giving attackers access to browser sessions, passwords, cloud and source-control tokens, deployment secrets, and cryptocurrency private keys. Researchers said the attackers moved assets across six blockchain networks within about an hour and later consolidated roughly 22.6 ETH in a staging wallet; the operation also used WebView2, password-protected archives, and executables disguised as PNG files to blend into normal workflow. The activity overlaps with a broader Google Workspace-themed intrusion ecosystem, but available evidence supports only a campaign relationship rather than confirmed attribution to a single actor.
Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.