Skip to main content
Mallory
MalwareRansomware

Elysium

Also known asElysium botnet

Elysium is malware consistently described in the provided content as a botnet, including as a relatively unknown proxy bot and as botnet infrastructure or an ecosystem used in international cybercrime. The content states that Elysium linked victim machines into controlled networks that could support distributed attacks, anonymity services, and scalable malware deployment. It is repeatedly mentioned alongside the Rhadamanthys infostealer and the VenomRAT remote access trojan as part of the same criminal infrastructure targeted by Europol-led Operation Endgame in November 2025. According to the content, authorities from multiple countries disrupted or took down Elysium between 10 and 13 November 2025, seizing or disabling more than 1,000 servers overall across the targeted malware families and seizing 20 domains. Europol is cited as stating that the targeted malware families, including Elysium, had infected hundreds of thousands of computers globally, enabled credential theft, remote access, and resale of stolen data, and played a key role in international cybercrime. One source in the content also describes Elysium as the enabler of the Rhadamanthys infostealer and VenomRAT. Another source characterizes it as a botnet variant of the Ghost ransomware family active since 2021. High-confidence indicators of compromise specific to Elysium are not provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583.001DomainsEvidence1

creating some new infrastructure including reviving the “RHAD Security” .onion site where he sells Rhadamanthys and other criminal services.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.