Rhadamanthys is a Windows malware-as-a-service information stealer first advertised on Russian-language cybercrime forums in September 2022 by an operator using the King Crete alias. It is a modular, multi-stage malware family with a development lineage that exhibits substantial architectural and code overlap with Hidden Bee. Rhadamanthys is used in broad financially motivated credential- and cryptocurrency-theft campaigns, commonly delivered through phishing, fake software-download sites promoted by malicious advertising, and social-engineering infection chains. It has also appeared as a secondary payload in loader-mediated compromises.
The malware collects host information, screenshots, browser credentials, cookies, browsing data, autofill records, saved payment-card data, browser extensions, and data from cryptocurrency wallet applications and browser wallet extensions. It targets credentials and data associated with password managers, KeePass, FTP and email clients, VPN clients, messaging applications, two-factor-authentication applications, remote-access tools, and other desktop software. Later versions added keylogging, collection from other local user accounts when permitted, file-grabbing capability, and OCR functionality intended to locate BIP39 cryptocurrency wallet recovery phrases in images and documents. Rhadamanthys can also execute attacker-supplied PowerShell, scripts, native payloads, and .NET assemblies.
Rhadamanthys employs custom module formats, encrypted configuration data, staged in-memory loading, process injection, custom virtual filesystem packages, and steganographic delivery of later stages in image or audio files. Its anti-analysis and defense-evasion features include virtual-machine obfuscation based on the Quake 3 VM, sandbox and debugger detection, API resolution obfuscation, NTDLL unhooking, raw and indirect syscalls, ETW and AMSI bypasses, and Heaven's Gate transitions for 64-bit execution from WoW64 contexts. It can establish persistence through host configuration changes and execute additional modules or commands received from command-and-control infrastructure. Rhadamanthys is associated with cybercriminal activity rather than a conclusively identified nation-state operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Details and IOCs Malware: ... Rhadamanthys ...
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this campaign, WasabiSeed is utilised to drop a number of files, ending with the Rhadamanthys Information Stealer.
Check Point Research is tracking an ongoing, large scale and sophisticated phishing campaign deploying the newest version of the Rhadamanthys stealer (0.7).
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
It is claimed that the Rhadamanthys Stealer is used and a loader for Traffers is provided.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
Deploy advanced endpoint detection and response (EDR) solutions to monitor for and block the execution of known malware families associated with Crazy Evil, such as Rhadamanthys, Stealc, and AMOS.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
Users encounter a CAPTCHA page that mimics a legitimate human verification prompt, often while browsing seemingly harmless content websites.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
In some cases, the phishing emails attach a PDF instead of including a direct link. Once opened, the PDF redirects the user to a fake CAPTCHA landing page.
The embedded URLs in each phishing email exploit the credibility of legitimate domains such as https://xxx[.]51.ca and hxxps://www[.]xxxnet.dk, to appear trustworthy to unsuspecting users. Once clicked, however, these URLs redirect users to the landing pages of the fake CAPTCHA domains.
Just like Hidden Bee, Rhadamanthys can run LUA scripts.
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command, which, in turn, connects to another site and executes multistage encoded scripts directly to the memory.
AI-Themed Brand Abuse A third category uses AI branding without meaningful AI integration. Filenames reference popular AI companies or other AI products, but the payload is conventional malware wrapped in an installer that mimics an AI application. The AI branding is a social engineering tactic, not a technical capability.
Many of the commands are responsible for loading/unloading certain modules and injection into other processes.
When lyricalsync.mp3 is executed via mshta, it initiates a multistage deobfuscation process designed to evade detection mechanisms.
The function denoted as parse_response is responsible for decoding the next stage that was downloaded from the C2 and hidden in a media file (JPG).
VM obfuscator. Heavy VM and sandbox detection capabilities... Zscaler investigators found that the VM obfuscator used is the Quake 3 VM.
A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products... The single most widely encountered sample was an installer posing as a recipe-finding app called Recipe Lister... Oyster backdoor, posed as a Dropbox installer.
Many of the commands are responsible for loading/unloading certain modules and injection into other processes.
0: Decode shellcode received as an argument... 3: Decrypt stage 2 using an algorithm of the TEA family
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command.
Before the connection is attempted, the malware calls a variety of different environment checks in order to evade sandboxes and other supervised environments.
KeePassHax C# module to exfiltrate credentials of password management software KeePass.
Fixed Discord token acquisition, the correct encrypted token can now be decoded. | Break through the browser data acquisition... add the login data decryption algorithm of 360 Secure Browser... The malware comes with a statically linked SQLite library which allows it to load and query local SQLite databases, and fetch saved data such as cookies.
A set of LUA scripts, which are used for extracting credentials.
1,350 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer delivered by a Windows executable; the observed sample maintained active command-and-control communications and had previously been tied to an AI-assisted infection chain.
Information stealer delivered by a .NET executable with active C2 communication; the report says it was part of an AI-enabled infection chain.
A popular infostealer mentioned in passing as part of broader market pressure from law enforcement actions.
An information stealer associated with the fake CAPTCHA campaign through overlapping delivery infrastructure and historical telemetry relationships.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.