Rhadamanthys Stealer, a well-known multi-modular information-stealing malware, has released version 0.9.2, which incorporates significant technical advancements aimed at evading detection and complicating analysis. The latest update introduces the use of PNG files as payload carriers, a technique that allows the malware to disguise its malicious components within seemingly innocuous image files, thereby bypassing traditional security controls that may not inspect image content for embedded threats. Security researchers have observed that this version also implements new anti-analysis tricks, making it more challenging for analysts and automated tools to dissect and understand the malware’s behavior. These anti-analysis features include enhanced obfuscation, custom executable formats, and string deobfuscation, all of which are designed to thwart reverse engineering efforts. The malware’s modular architecture remains intact, allowing threat actors to customize and deploy various functionalities depending on their objectives. Rhadamanthys has been actively used in multiple cybercrime campaigns since its initial release in 2022, and its continued evolution demonstrates the sophistication and adaptability of its developers. The malware’s popularity on underground forums has led to its adoption by a wide range of threat actors, including those with advanced capabilities. Security researchers from Check Point have provided tools and scripts to help defenders adapt to these changes, including converters for the new executable format and unpackers for the updated module packages. The use of PNG payloads is particularly concerning, as it leverages a common file type to evade detection and can be distributed through various channels, including phishing emails and compromised websites. The anti-analysis enhancements mean that defenders must update their detection and response strategies to account for these new evasion techniques. The malware’s ability to steal credentials, exfiltrate sensitive data, and provide remote access to compromised systems continues to pose a significant threat to organizations. The rapid pace of development and the introduction of novel techniques in version 0.9.2 underscore the need for continuous monitoring and adaptation by security teams. Researchers emphasize the importance of threat intelligence sharing and the use of updated detection tools to mitigate the risks posed by Rhadamanthys. The ongoing updates to Rhadamanthys highlight the broader trend of malware authors adopting increasingly sophisticated methods to bypass security controls and hinder analysis. Organizations are advised to review their security controls, ensure endpoint protection solutions are updated, and educate users about the risks associated with opening suspicious files, even those that appear to be harmless images. The technical community continues to monitor Rhadamanthys for further developments, as its evolution is likely to influence the tactics of other malware families in the cybercrime ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A follow-up report described Rhadamanthys Stealer v0.9.2 as adding new PNG-based payload delivery and anti-analysis techniques, indicating a further iteration in the malware's development. The coverage framed these changes as making the malware more evasive and dangerous.
Check Point Research published an analysis of Rhadamanthys 0.9.x, describing updates to the stealer's capabilities and evolution. The report indicates the malware had already introduced meaningful changes in the 0.9.x branch by the time of publication.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.