Rhadamanthys is a modular Windows information stealer marketed in criminal forums since 2022 and maintained through frequent feature and anti-analysis updates. It targets browser credentials, cookies and session data, cryptocurrency-wallet clients and browser extensions, password-manager data including KeePass, FTP and mail-client data, two-factor-authentication application data, messaging data, screenshots, host information, and selected files. Recent variants include OCR functionality intended to locate BIP39 cryptocurrency wallet recovery phrases in documents and images.
The malware uses a staged loader architecture, custom executable formats, an embedded virtual filesystem, encrypted configuration and payload data, and steganographic retrieval of later-stage modules. It has substantial defense-evasion functionality, including virtual-machine-based code obfuscation derived from the Quake 3 VM, sandbox and analysis-tool checks, API hashing, user-mode hook detection or bypassing, AMSI bypassing, Heaven’s Gate transitions, and process injection. Lua extensions and .NET components provide additional collection and execution functionality.
Rhadamanthys has been delivered through phishing and targeted spearphishing campaigns, password-protected archives, DLL sideloading, fake software-download sites promoted through malicious advertising or search-engine poisoning, and ClickFix-style fake CAPTCHA lures. The CopyRh(ight)adamantys campaign distributed version 0.7 through copyright-infringement-themed phishing and was assessed as financially motivated cybercrime activity. Technical overlap with Hidden Bee, including custom module formats and loader architecture, indicates a likely shared development lineage. Rhadamanthys is also used as a final payload by multiple unrelated loader and malware-delivery ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Details and IOCs Malware: ... Rhadamanthys ...
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this campaign, WasabiSeed is utilised to drop a number of files, ending with the Rhadamanthys Information Stealer.
Check Point Research is tracking an ongoing, large scale and sophisticated phishing campaign deploying the newest version of the Rhadamanthys stealer (0.7).
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
Deploy advanced endpoint detection and response (EDR) solutions to monitor for and block the execution of known malware families associated with Crazy Evil, such as Rhadamanthys, Stealc, and AMOS.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
Users encounter a CAPTCHA page that mimics a legitimate human verification prompt, often while browsing seemingly harmless content websites.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
In some cases, the phishing emails attach a PDF instead of including a direct link. Once opened, the PDF redirects the user to a fake CAPTCHA landing page.
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command, which, in turn, connects to another site and executes multistage encoded scripts directly to the memory.
AI-Themed Brand Abuse A third category uses AI branding without meaningful AI integration. Filenames reference popular AI companies or other AI products, but the payload is conventional malware wrapped in an installer that mimics an AI application. The AI branding is a social engineering tactic, not a technical capability.
Many of the commands are responsible for loading/unloading certain modules and injection into other processes.
When lyricalsync.mp3 is executed via mshta, it initiates a multistage deobfuscation process designed to evade detection mechanisms.
SHELLTER-protected samples commonly employ self-modifying shellcode with polymorphic obfuscation... legitimate instructions and polymorphic code helps these files evade static detection and signatures.
The function denoted as parse_response is responsible for decoding the next stage that was downloaded from the C2 and hidden in a media file (JPG).
VM obfuscator. Heavy VM and sandbox detection capabilities... Zscaler investigators found that the VM obfuscator used is the Quake 3 VM.
A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products... The single most widely encountered sample was an installer posing as a recipe-finding app called Recipe Lister... Oyster backdoor, posed as a Dropbox installer.
Many of the commands are responsible for loading/unloading certain modules and injection into other processes.
0: Decode shellcode received as an argument... 3: Decrypt stage 2 using an algorithm of the TEA family
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command.
Before the connection is attempted, the malware calls a variety of different environment checks in order to evade sandboxes and other supervised environments.
KeePassHax C# module to exfiltrate credentials of password management software KeePass.
Fixed Discord token acquisition, the correct encrypted token can now be decoded. | Break through the browser data acquisition... add the login data decryption algorithm of 360 Secure Browser... The malware comes with a statically linked SQLite library which allows it to load and query local SQLite databases, and fetch saved data such as cookies.
A set of LUA scripts, which are used for extracting credentials.
The report identifies a C++ loader client abusing BITS for C2 and lists LUMMA, ARECHCLIENT2, and RHADAMANTHYS command-and-control infrastructure.
The URL used to contact the C2 is obtained from the config. It is used to fetch Stage 3
1,350 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer delivered by a Windows executable; the observed sample maintained active command-and-control communications and had previously been tied to an AI-assisted infection chain.
Information stealer delivered by a .NET executable with active C2 communication; the report says it was part of an AI-enabled infection chain.
A popular infostealer mentioned in passing as part of broader market pressure from law enforcement actions.
An information stealer associated with the fake CAPTCHA campaign through overlapping delivery infrastructure and historical telemetry relationships.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.