Rhadamanthys is a malware-as-a-service infostealer operated by financially motivated cybercriminals. It is used to compromise large numbers of victim systems and exfiltrate sensitive data, making it part of the broader criminal ecosystem centered on credential theft, data harvesting, and downstream fraud. The operation is commonly referred to as Rhadamanthys, and associated references include Rhadamanthys infostealer and Rhadamanthys infostealer operators. The threat activity associated with Rhadamanthys is characterized by large-scale infections and centralized criminal infrastructure supporting malware deployment and stolen-data collection. As an infostealer operation, it is associated with the theft of credentials and other sensitive information from infected devices, enabling follow-on abuse such as account compromise, financial fraud, and resale of stolen data in criminal markets. Its operational model aligns with other service-based cybercrime offerings in which malware capability and infrastructure are provided to affiliates or customers. Rhadamanthys has been significant enough to become a target of multinational law-enforcement action. During Operation Endgame in 2025, authorities disrupted infrastructure linked to the malware, taking down more than a thousand servers and arresting a suspect connected to the operation. This places Rhadamanthys among the more prominent contemporary cybercriminal malware operations targeted through coordinated international disruption efforts. No high-confidence attribution to a nation state is established in the available information. Rhadamanthys is best understood as a financially motivated cybercriminal operation rather than a state-directed threat group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators of the Rhadamanthys infostealer used the malware to infect devices worldwide and steal sensitive data, supporting various cybercrime groups.
Rhadamanthys infostealer is a malware family that was targeted and disrupted by a major law enforcement operation in November 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.