Threat researchers reported two active intrusion patterns aimed at stealing credentials and maintaining access: a malvertising campaign that impersonated software brands such as Notion in Google search ads to deliver Rhadamanthys on Windows and Atomic Stealer on macOS, and a separate cyber-espionage operation by Mantis (also tracked as Arid Viper, Desert Falcon, and APT-C-23) targeting organizations in the Palestinian territories. In the malvertising chain, victims were redirected through intermediary domains, screened with browser-based anti-VM checks, and sent to fake download pages; the Windows installer fetched its payload from a URL hosted on TextBin, while researchers linked the advertiser account to “BUDNIK PAWEŁ” in Poland and noted thousands of views of the staging URL.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A fraudulent Google search ad impersonating Notion and linked to an advertiser account identified as “BUDNIK PAWEŁ” from Poland first appeared. The campaign redirected users through intermediary domains and ultimately delivered Rhadamanthys to Windows users and a new Atomic Stealer variant to macOS users.
Symantec reported that the Mantis espionage group continued operations in a campaign spanning 2022 to 2023 against organizations in the Palestinian territories. The attackers used updated Micropsia and Arid Gopher backdoors, credential theft, persistence mechanisms, reverse SOCKS tunneling, and a custom exfiltration tool.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.