Skip to content
Malware family Windows

Rhadamanthys

Rhadamanthys is a Windows information-stealing malware family written in C++ that has been active since late 2022 and is commonly offered through malware-as-a-service subscription models.

Profile source: Mallory opens in a new tab

Rhadamanthys

Family profile

Rhadamanthys is a Windows information-stealing malware family written in C++ that has been active since late 2022 and is commonly offered through malware-as-a-service subscription models. It is used to collect and exfiltrate sensitive data from infected systems, including browser credentials and cookies, system information, cryptocurrency wallet data, and information from a broad range of desktop applications such as password managers, VPN clients, FTP clients, messaging platforms, email clients, gaming platforms, and file-transfer tools. Reported targeting includes cryptocurrency-focused victims, business users, and enterprise environments where follow-on compromise can enable broader intrusion activity.

Rhadamanthys is distributed through multiple criminal delivery channels, including phishing and malspam, malicious online advertisements, fake software installers and updates, cracked or pirated software, drive-by and loader-based infection chains, and deceptive landing pages that impersonate legitimate software brands. It has also been observed as a final payload delivered by other malware and access services, including Dolphin Loader, GHOSTPULSE, TA866-associated chains, and broader stealer-traffer ecosystems.

Technically, Rhadamanthys commonly uses staged execution and strong defense-evasion tradecraft. Documented samples include packed droppers, in-memory shellcode decryption and execution, callback-based shellcode launch, anti-VM and anti-analysis checks, suppression of error dialogs, mutex masquerading, dynamic API resolution, and user-mode unhooking or inspection of security-related modules. Some observed chains use AutoIt intermediates, DLL execution via rundll32, and process injection to launch or protect the final stealer. The malware communicates with command-and-control infrastructure to transmit stolen data and can receive additional tasking or payloads.

Rhadamanthys has been associated with financially motivated cybercrime operations and has appeared in campaigns linked to malvertising crews, traffer teams, and threat actors such as TA866. It has also been used alongside other commodity stealers and loaders including Lumma, Vidar, StealC, RedLine, SectopRAT, DarkGate, and NetSupport. Its prevalence made it one of the more prominent infostealer services in 2025 before major law-enforcement disruption efforts, including Operation Endgame, targeted infrastructure associated with the malware.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Process Injection

Reported operators

Threat actors

13 named in public reporting
Dungeon

It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.

TA866

Rhadamanthys is an information stealer that can be used to collect and exfiltrate a variety of sensitive data from infected systems.

Aggah

This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.

Crazy Evil

Deploy advanced endpoint detection and response (EDR) solutions to monitor for and block the execution of known malware families associated with Crazy Evil, such as Rhadamanthys, Stealc, and AMOS.

Handala

It also recently added a commercial infostealer - Rhadamanthys - sold on cybercrime forums to its arsenal, according to Check Point.

TA2541

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

TA547

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

TA585

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

TA571

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

MOIST GRASSHOPPER

Tools like Rhadamanthys, a commercial infostealer available on darknet forums, appeared in Handala-linked operations paired with custom wipers in phishing campaigns impersonating software updates from vendors such as F5.

SCULLY SPIDER

Proofpoint in April, who suspected TA547 (aka "Scully Spider") of deploying an AI-written PowerShell loader for their final payload, Rhadamanthys info-stealer.

EncryptHub

EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.

Indrik Spider

In a number of cases, we observed attempts to use NetSupport RAT to install stealers such as Rhadamanthys and Meduza.

Exploited software

Vulnerabilities linked to Rhadamanthys

1 CVEs

MITRE ATT&CK

Rhadamanthys in ATT&CK

79 distinct techniques

Techniques

79 techniques
T1059 Command and Scripting Interpreter T1105 Ingress Tool Transfer T1560 Archive Collected Data T1204.002 Malicious File T1497.001 System Checks T1055 Process Injection T1562.001 Disable or Modify Tools T1189 Drive-by Compromise T1649 Steal or Forge Authentication Certificates T1657 Financial Theft T1036 Masquerading T1555 Credentials from Password Stores T1012 Query Registry T1218.011 Rundll32 T1140 Deobfuscate/Decode Files or Information T1528 Steal Application Access Token T1027.007 Dynamic API Resolution T1480.002 Mutual Exclusion T1112 Modify Registry T1555.003 Credentials from Web Browsers T1071 Application Layer Protocol T1106 Native API T1562 Impair Defenses T1059.001 PowerShell T1566.002 Spearphishing Link T1583 Acquire Infrastructure T1553 Subvert Trust Controls T1218.005 Mshta T1588 Obtain Capabilities T1005 Data from Local System T1204 User Execution T1566 Phishing T1059.007 JavaScript T1598 Phishing for Information T1041 Exfiltration Over C2 Channel T1027.016 Junk Code Insertion T1218 System Binary Proxy Execution T1547.009 Shortcut Modification T1059.003 Windows Command Shell T1539 Steal Web Session Cookie T1556 Modify Authentication Process T1078 Valid Accounts T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1485 Data Destruction T1132 Data Encoding T1033 System Owner/User Discovery T1518 Software Discovery T1027.003 Steganography T1082 System Information Discovery T1057 Process Discovery T1027 Obfuscated Files or Information T1071.001 Web Protocols T1102 Web Service T1113 Screen Capture T1036.005 Match Legitimate Resource Name or Location T1056.001 Keylogging T1125 Video Capture T1553.002 Code Signing T1583.003 Virtual Private Server T1218.007 Msiexec T1070.004 File Deletion T1559.001 Component Object Model T1547.001 Registry Run Keys / Startup Folder T1053.005 Scheduled Task T1573 Encrypted Channel T1497 Virtualization/Sandbox Evasion T1213 Data from Information Repositories T1190 Exploit Public-Facing Application T1584 Compromise Infrastructure T1614 System Location Discovery T1583.001 Domains T1548.002 Bypass User Account Control T1059.006 Python T1620 Reflective Code Loading T1027.002 Software Packing T1008 Fallback Channels T1071.004 DNS T1110.004 Credential Stuffing

Reporting

Research mentioning Rhadamanthys

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Rhadamanthys3

Jun 24
Bank Info Security

Infostealers StealC and Amadey Disrupted in Police Crackdown

Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.

Jun 24
Bleeping Computer

Amadey, StealC malware operations disrupted in Operation Endgame action

The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.

Jun 24
Govinfosecurity

Infostealers StealC and Amadey Disrupted in Police Crackdown

Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.

Jun 22
Xakep

Правоохранители очистили 15 000 сайтов, зараженных SocGholish - Хакер

Напомним, что в прошлом году в рамках операции «Эндшпиль» были отключены более 1000 серверов, связанных с Rhadamanthys, VenomRAT и Elysium.

Jun 18
Hackread

Operation Endgame Disrupts SocGholish Malware Infrastructure

police shut down over 1,025 servers used by three other malware groups, terminating the core infrastructure of the Rhadamanthys infostealer, the VenomRAT remote control tool, and the Elysium botnet

Jun 18
Bleeping Computer

Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp

In November, as part of Operation Endgame, law enforcement agencies also took down over 1,000 servers used by the Rhadamanthys, VenomRAT, and Elysium botnet malware operations.

Jun 7
Codeby

Атаки через украденные учётные данные: kill chain 2024

Rhadamanthys - заменил LummaC2 в некоторых панелях управления после правоприменительных действий

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.