Rhadamanthys is a Windows information-stealing malware family offered as a malware-as-a-service operation since 2022 and widely used in financially motivated cybercrime. It is modular, frequently updated, and commonly delivered through phishing, malvertising, fake software or update lures, password-protected archives, and DLL sideloading chains. Campaigns have also used search-engine ads, cracked-software themes, and ClickFix-style social engineering to distribute it.
The malware is built as a multi-stage loader and stealer framework with strong anti-analysis features. Reported variants use shellcode, custom executable formats, process injection, Heaven’s Gate transitions, raw or indirect syscalls, unhooking, ETW and AMSI bypasses, and environment checks derived in part from public anti-analysis tooling. Some versions use a Quake 3 virtual-machine-based obfuscation layer, while later stages may be delivered steganographically inside image or audio files. Rhadamanthys has also been linked technically to the older Hidden Bee lineage through overlapping custom formats, virtual filesystem design, module structure, and loading logic.
Its core function is broad credential and data theft. Rhadamanthys steals browser credentials, cookies, autofill data, browsing artifacts, session material, cryptocurrency wallet data, FTP and mail client credentials, password-manager data, VPN credentials, messaging-app data, screenshots, host inventory, and selected files. It has shown particular emphasis on cryptocurrency theft, targeting both desktop wallet applications and browser wallet extensions. Documented modules include functionality for KeePass credential theft, PowerShell execution, Lua-based extension loading, and task execution of additional payload types. Newer releases expanded beyond classic infostealing with plugin support, keylogging, observer or spying features, and a clipper plugin in later versions.
Recent versions introduced OCR-oriented functionality apparently intended to identify cryptocurrency seed phrases in images or documents, especially BIP39 recovery phrases. Rhadamanthys can also receive commands from its command-and-control infrastructure to execute follow-on tasks or load additional modules, making it useful both as a standalone infostealer and as part of broader intrusion chains.
Rhadamanthys has been observed in campaigns targeting individuals and organizations across multiple sectors and regions, including technology, media, healthcare, manufacturing, finance, government, and cryptocurrency-related entities. Attribution in public reporting most consistently supports financially motivated cybercrime usage rather than a single state actor, although the malware appears in diverse affiliate and loader ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Details and IOCs Malware: ... Rhadamanthys ...
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this campaign, WasabiSeed is utilised to drop a number of files, ending with the Rhadamanthys Information Stealer.
Check Point Research is tracking an ongoing, large scale and sophisticated phishing campaign deploying the newest version of the Rhadamanthys stealer (0.7).
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
Deploy advanced endpoint detection and response (EDR) solutions to monitor for and block the execution of known malware families associated with Crazy Evil, such as Rhadamanthys, Stealc, and AMOS.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Just like Hidden Bee, Rhadamanthys can run LUA scripts.
the modified syscalls allow the virtualized code to interact with key components of the native program, enabling to read the memory space of kernel32.dll and resolving its exports
For this purpose, the author decided to use a shared memory area that is accessed by different processes via named mapping.
Many of the commands are responsible for loading/unloading certain modules and injection into other processes.
Rhadamanthys uses a virtual machine (Q3VM) in order to obfuscate its code and hide certain code details.
The function denoted as parse_response is responsible for decoding the next stage that was downloaded from the C2 and hidden in a media file (JPG).
VM obfuscator. Heavy VM and sandbox detection capabilities... Zscaler investigators found that the VM obfuscator used is the Quake 3 VM.
Loads the Windows API functions GetProcAddress and VirtualProtect by using the ROR-13 hashing technique.
This DLL is further dropped into the %APPDATA% directory, disguised as a DLL related to NSIS installers.
Many of the commands are responsible for loading/unloading certain modules and injection into other processes.
After the loading is finished, the module erases its own header in order to make it more difficult to dump and reconstruct it from memory.
0: Decode shellcode received as an argument... 3: Decrypt stage 2 using an algorithm of the TEA family
Depending on the Windows version, it may try to rerun itself with elevated privileges, using runas.
Before the connection is attempted, the malware calls a variety of different environment checks in order to evade sandboxes and other supervised environments.
The other 2 checks are very similar and use the cpuid instruction with the parameter 0x40000000, which should return no results on physical machines. | Rhadamanthys’ loader will check for the presence of Avast AV before executing its next stage.
The first check compares the time the victim machine takes to execute the cpuid instruction against the performance of the fyl2xp1 instruction.
KeePassHax C# module to exfiltrate credentials of password management software KeePass.
Fixed Discord token acquisition, the correct encrypted token can now be decoded. | Break through the browser data acquisition... add the login data decryption algorithm of 360 Secure Browser... The malware comes with a statically linked SQLite library which allows it to load and query local SQLite databases, and fetch saved data such as cookies.
before the vital part is unpacked, the main executable examines its environment by enumerating running processes and comparing them against the list of known analysis tools
A set of LUA scripts, which are used for extracting credentials.
Before the connection is attempted, the malware calls a variety of different environment checks in order to evade sandboxes and other supervised environments.
All of these stealing actions are performed automatically upon infection. If the attacker decides to get more hands-on with the infected machine, they can push a new configuration to the “file grabbing” module, which will exfiltrate all files matching a windows search query
1,327 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware discussed in a malware analysis entry focused on deobfuscation of the Rhadamanthys loader.
Mentioned as an example of malware previously hidden in PNG-image steganography in other ClickFix campaigns.
Infostealer that steals browser passwords, active session cookies, and autofill data; the article says it was affected by Operation Endgame in November 2025 but such families often resume activity.
Rhadamanthys3
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.