Skip to content

Rhadamanthys

Rhadamanthys is a Windows malware-as-a-service information stealer first advertised on Russian-language cybercrime forums in September 2022 by an operator using the King Crete alias.

Profile source: Mallory opens in a new tab

Rhadamanthys

Family profile

Rhadamanthys is a Windows malware-as-a-service information stealer first advertised on Russian-language cybercrime forums in September 2022 by an operator using the King Crete alias. It is a modular, multi-stage malware family with a development lineage that exhibits substantial architectural and code overlap with Hidden Bee. Rhadamanthys is used in broad financially motivated credential- and cryptocurrency-theft campaigns, commonly delivered through phishing, fake software-download sites promoted by malicious advertising, and social-engineering infection chains. It has also appeared as a secondary payload in loader-mediated compromises.

The malware collects host information, screenshots, browser credentials, cookies, browsing data, autofill records, saved payment-card data, browser extensions, and data from cryptocurrency wallet applications and browser wallet extensions. It targets credentials and data associated with password managers, KeePass, FTP and email clients, VPN clients, messaging applications, two-factor-authentication applications, remote-access tools, and other desktop software. Later versions added keylogging, collection from other local user accounts when permitted, file-grabbing capability, and OCR functionality intended to locate BIP39 cryptocurrency wallet recovery phrases in images and documents. Rhadamanthys can also execute attacker-supplied PowerShell, scripts, native payloads, and .NET assemblies.

Rhadamanthys employs custom module formats, encrypted configuration data, staged in-memory loading, process injection, custom virtual filesystem packages, and steganographic delivery of later stages in image or audio files. Its anti-analysis and defense-evasion features include virtual-machine obfuscation based on the Quake 3 VM, sandbox and debugger detection, API resolution obfuscation, NTDLL unhooking, raw and indirect syscalls, ETW and AMSI bypasses, and Heaven's Gate transitions for 64-bit execution from WoW64 contexts. It can establish persistence through host configuration changes and execute additional modules or commands received from command-and-control infrastructure. Rhadamanthys is associated with cybercriminal activity rather than a conclusively identified nation-state operator.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 30, 2026
Last activity
Sep 6, 2026
Feed role
C2 / Distribution
Host form
21 IP / 6 hostnames

Leading locations

  • DE9
  • CN5
  • US4
  • KR2
  • NL2
  • FR1
  • GB1
  • IN1
  • RU1
  • SG1

Leading providers

  • FEMO IT SOLUTIONS LIMITED6
  • Omegatech LTD4
  • CHINA UNICOM China169 Backbone3
  • SK Broadband Co Ltd2
  • Amazon.com, Inc.1
  • Bouygues Telecom SA1

Infrastructure traits

  • Hosting 20
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

14 named in public reporting
TA866

In this campaign, WasabiSeed is utilised to drop a number of files, ending with the Rhadamanthys Information Stealer.

Handala

Check Point Research is tracking an ongoing, large scale and sophisticated phishing campaign deploying the newest version of the Rhadamanthys stealer (0.7).

Marko Polo

Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias โ€˜markopoloโ€™, an IAB spreading StealC, Rhadamanthys and Atomic

Dungeon

It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.

Aggah

This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.

Crazy Evil

Deploy advanced endpoint detection and response (EDR) solutions to monitor for and block the execution of known malware families associated with Crazy Evil, such as Rhadamanthys, Stealc, and AMOS.

TA2541

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

TA547

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

TA585

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

TA571

Rhadamanthys is a prominent malware observed since 2022, used by multiple cybercriminal threat actors. It is a modular information stealer with multiple pricing plans, and the creators sell it alongside Elysium Proxy Bot and a Crypt Service.

MOIST GRASSHOPPER

Tools like Rhadamanthys, a commercial infostealer available on darknet forums, appeared in Handala-linked operations paired with custom wipers in phishing campaigns impersonating software updates from vendors such as F5.

SCULLY SPIDER

Proofpoint in April, who suspected TA547 (aka "Scully Spider") of deploying an AI-written PowerShell loader for their final payload, Rhadamanthys info-stealer.

EncryptHub

EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.

Mustard Tempest

In a number of cases, we observed attempts to use NetSupport RAT to install stealers such as Rhadamanthys and Meduza.

Exploited software

Vulnerabilities linked to Rhadamanthys

1 CVEs

MITRE ATT&CK

Rhadamanthys in ATT&CK

90 distinct techniques

Techniques

90 techniques
T1071 Application Layer Protocol T1036 Masquerading T1204 User Execution T1027 Obfuscated Files or Information T1620 Reflective Code Loading T1059.001 PowerShell T1583.001 Domains T1608.006 SEO Poisoning T1566.002 Spearphishing Link T1566 Phishing T1105 Ingress Tool Transfer T1218.005 Mshta T1583 Acquire Infrastructure T1189 Drive-by Compromise T1204.002 Malicious File T1566.001 Spearphishing Attachment T1555.003 Credentials from Web Browsers T1497.001 System Checks T1071.001 Web Protocols T1140 Deobfuscate/Decode Files or Information T1041 Exfiltration Over C2 Channel T1027.006 HTML Smuggling T1027.003 Steganography T1547.001 Registry Run Keys / Startup Folder T1497 Virtualization/Sandbox Evasion T1548.002 Bypass User Account Control T1555 Credentials from Password Stores T1055 Process Injection T1559.001 Component Object Model T1083 File and Directory Discovery T1059 Command and Scripting Interpreter T1218 System Binary Proxy Execution T1070.004 File Deletion T1574 Hijack Execution Flow T1027.007 Dynamic API Resolution T1497.003 Time Based Checks T1057 Process Discovery T1129 Shared Modules T1106 Native API T1113 Screen Capture T1005 Data from Local System T1555.005 Password Managers T1560 Archive Collected Data T1059.005 Visual Basic T1218.011 Rundll32 T1082 System Information Discovery T1562.001 Disable or Modify Tools T1056.001 Keylogging T1622 Debugger Evasion T1059.007 JavaScript T1115 Clipboard Data T1559 Inter-Process Communication T1003 OS Credential Dumping T1547.009 Shortcut Modification T1539 Steal Web Session Cookie T1649 Steal or Forge Authentication Certificates T1657 Financial Theft T1012 Query Registry T1528 Steal Application Access Token T1480.002 Mutual Exclusion T1112 Modify Registry T1562 Impair Defenses T1553 Subvert Trust Controls T1588 Obtain Capabilities T1598 Phishing for Information T1027.016 Junk Code Insertion T1059.003 Windows Command Shell T1556 Modify Authentication Process T1078 Valid Accounts T1485 Data Destruction T1132 Data Encoding T1033 System Owner/User Discovery T1518 Software Discovery T1102 Web Service T1036.005 Match Legitimate Resource Name or Location T1125 Video Capture T1553.002 Code Signing T1583.003 Virtual Private Server T1218.007 Msiexec T1053.005 Scheduled Task T1573 Encrypted Channel T1213 Data from Information Repositories T1190 Exploit Public-Facing Application T1584 Compromise Infrastructure T1614 System Location Discovery T1059.006 Python T1027.002 Software Packing T1008 Fallback Channels T1071.004 DNS T1110.004 Credential Stuffing

Reporting

Research mentioning Rhadamanthys

Aug 17
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A targeted social-engineering campaign compromised a cryptocurrency organization after a Windows employee was lured through a fake Web3 hiring process that began with LinkedIn recruiter outreach and moved through Calendly scheduling to a bogus Google Workspace-style technical assessment. The assessment redirected the victim to install a signed Microsoft ClickOnce application, GapiUpdate.application, which used trusted Windows deployment behavior and Google-themed presentation to appear legitimate. The infection chain deployed NeedleStealer, a Rust-based information stealer, and a Go-based hVNC RAT, giving attackers access to browser sessions, passwords, cloud and source-control tokens, deployment secrets, and cryptocurrency private keys. Researchers said the attackers moved assets across six blockchain networks within about an hour and later consolidated roughly 22.6 ETH in a staging wallet; the operation also used WebView2, password-protected archives, and executables disguised as PNG files to blend into normal workflow. The activity overlaps with a broader Google Workspace-themed intrusion ecosystem, but available evidence supports only a campaign relationship rather than confirmed attribution to a single actor.

Aug 17
Cyber Security News

Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT

Aug 17
Cryptika

Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT | Cryptika Cybersecurity

Jul 24
Security Online Info

ACR Stealer Spreads Through ClickFix Lures

Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.

Jul 18
Bleeping Computer

Microsoft warns of surge in ACR Stealer attacks on customers

Jul 17
Scworld

ACR Stealer exploits user interaction to steal sensitive data | brief | SC Media

Jul 17
The Hacker News

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

Jul 17
Trojan Killer News

ACR Stealer ClickFix Campaign Uses WebDAV and MSHTA

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.