Rhadamanthys is a Windows information stealer used for credential theft, session compromise, and cryptocurrency theft. It collects and exfiltrates browser credentials and session information, KeePass credentials, cryptocurrency-wallet data, and information about compromised computers. Its capabilities include optical character recognition for extracting sensitive information, including wallet mnemonic phrases, from images and PDFs. Version 0.9.1 includes AI-assisted stolen-data tagging, filtering, and operator-dashboard analytics, alongside wallet-password recovery, brute-force automation, keylogging, and cryptocurrency transaction hijacking. Evasion features include memory-resident execution, reflective loading, and bypasses for Antimalware Scan Interface and Event Tracing for Windows.
Rhadamanthys is distributed through phishing, deceptive software-download sites, gaming-related lures, fake CAPTCHA ClickFix campaigns, and multistage loaders. Document-themed delivery chains abuse Microsoft Management Console Taskpad functionality to retrieve and execute PowerShell scripts carrying the payload; this method does not require exploiting a vulnerability. Other campaigns exploit CVE-2023-38831 in WinRAR through specially crafted archives. Associated delivery tools include GHOSTPULSE, Matanbuchus, RenEngine Loader, and Shellter-protected executables. Meowsterio has deployed Rhadamanthys through deceptive websites and weaponized ClickOnce applications. Sandworm, associated with Russia's GRU Unit 74455, has used it in invitation-themed phishing impersonating a Ukrainian drone warfare training school.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-38831, the WinRAR zero-day remote code execution vulnerability, has been exploited in the wild to distribute several malware families.
Threat Details and IOCs Malware: ... Rhadamanthys ...
16 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Meowsterio relies on infostealers such as StealC and Rhadamanthys to steal victim computer information and cryptocurrencies wallets data.
Rhadamanthys is an infostealer malware which has the capability to collect and exfiltrate browser credentials and session information.
In this campaign, WasabiSeed is utilised to drop a number of files, ending with the Rhadamanthys Information Stealer.
Check Point Research is tracking an ongoing, large scale and sophisticated phishing campaign deploying the newest version of the Rhadamanthys stealer (0.7).
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
Users encounter a CAPTCHA page that mimics a legitimate human verification prompt, often while browsing seemingly harmless content websites.
These tactics range from using phishing emails containing malicious ZIP files to deploying different families of malware.
In some cases, the phishing emails attach a PDF instead of including a direct link. Once opened, the PDF redirects the user to a fake CAPTCHA landing page.
Upon exploiting the successful vulnerability, it leads to BAT file execution, which pretends to be a PDF file.
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command, which, in turn, connects to another site and executes multistage encoded scripts directly to the memory.
When a victim double-clicks on the PDF, the vulnerability will quietly launch a script in the folder to install malware on the device.
AI-Themed Brand Abuse A third category uses AI branding without meaningful AI integration. Filenames reference popular AI companies or other AI products, but the payload is conventional malware wrapped in an installer that mimics an AI application. The AI branding is a social engineering tactic, not a technical capability.
When lyricalsync.mp3 is executed via mshta, it initiates a multistage deobfuscation process designed to evade detection mechanisms.
SHELLTER-protected samples commonly employ self-modifying shellcode with polymorphic obfuscation... legitimate instructions and polymorphic code helps these files evade static detection and signatures.
The function denoted as parse_response is responsible for decoding the next stage that was downloaded from the C2 and hidden in a media file (JPG).
VM obfuscator. Heavy VM and sandbox detection capabilities... Zscaler investigators found that the VM obfuscator used is the Quake 3 VM.
A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products... The single most widely encountered sample was an installer posing as a recipe-finding app called Recipe Lister... Oyster backdoor, posed as a Dropbox installer.
0: Decode shellcode received as an argument... 3: Decrypt stage 2 using an algorithm of the TEA family
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command.
The report identifies a C++ loader client abusing BITS for C2 and lists LUMMA, ARECHCLIENT2, and RHADAMANTHYS command-and-control infrastructure.
The URL used to contact the C2 is obtained from the config. It is used to fetch Stage 3
1,359 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned solely as a possible antivirus verdict label; the analysis identifies the analyzed payload as Vidar-class rather than Rhadamanthys.
Infostealer associated with Operation Endgame Phase 3. The dataset found no measurable post-operation response, in part because its observed volume was negligible.
Information stealer delivered by a Windows executable; the observed sample maintained active command-and-control communications and had previously been tied to an AI-assisted infection chain.
Information-stealing malware included in the research on AI-enabled malware. The summary does not identify the information it steals or specify its AI capabilities or production activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.