Rhadamanthys, a prominent information-stealing malware, has undergone significant evolution, expanding its capabilities and threat profile. Initially promoted on cybercrime forums by a threat actor known as kingcrete2022, Rhadamanthys has become a leading malware-as-a-service (MaaS) offering, rivaling other popular stealers such as Lumma, Vidar, StealC, and Acreed. The malware's latest version, 0.9.2, introduces advanced features including device and web browser fingerprinting, as well as the use of PNG steganography for payload delivery, enhancing its ability to evade detection and exfiltrate sensitive data. Previous updates, such as version 0.7.0, incorporated artificial intelligence-based optical character recognition (OCR) to capture cryptocurrency wallet seed phrases, demonstrating the developers' commitment to integrating cutting-edge techniques. The operators have rebranded as "RHAD security" and "Mythical Origin Labs," marketing Rhadamanthys as an "intelligent solution" and offering it in tiered packages ranging from $299 to $499 per month, with an enterprise option available for direct negotiation. This business-like approach, including a structured product portfolio and customer support, signals a long-term strategy to maintain and grow their presence in the cybercrime ecosystem. The stealer is distributed through various channels, including fake software and phishing campaigns, targeting both individuals and organizations. Its modular architecture allows for rapid adaptation to new security measures, making it a persistent threat. Security researchers have observed that Rhadamanthys is frequently updated, with new features aimed at bypassing modern defenses and increasing the value proposition for cybercriminal customers. The malware's ability to collect a wide range of credentials, financial information, and system data poses significant risks to both personal and corporate security. Defensive measures must account for its evolving tactics, including the use of steganography and AI-driven data extraction. The growing sophistication and commercialization of Rhadamanthys reflect broader trends in the cybercrime-as-a-service market, where threat actors continuously innovate to outpace defenders. Organizations are urged to implement robust endpoint protection, monitor for indicators of compromise, and educate users about the risks of downloading software from untrusted sources. The ongoing development and aggressive marketing of Rhadamanthys underscore the need for continuous vigilance and adaptive security strategies in the face of rapidly evolving malware threats.

Pull IOCs and campaign context straight into your stack.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.