Rhadamanthys emerged as a fast-growing malware-as-a-service infostealer sold on criminal forums, using aggressive promotion and frequent updates to attract operators. Researchers found it delivered through lures including fake AnyDesk installers and malicious Google Ads, then executed through a multi-stage chain involving packed droppers, shellcode, custom loaders, VM-evasion, API unhooking, and obfuscated command-and-control retrieval. The malware was observed attempting infections beyond broad consumer targeting, including a Canadian government agency and an Indian energy company, while generally avoiding CIS targets.
Technical analysis showed Rhadamanthys stealing credentials, cookies, browser data, and information from password managers, VPNs, messaging apps, email clients, FTP tools, gaming platforms, and cryptocurrency wallets. Later versions, including v0.5.0, added a plugin architecture, keylogging, spyware-like data collection, Lua and .NET extensions, process injection, raw and indirect syscalls, Heaven’s Gate, and ETW/AMSI bypasses, allowing operators to fetch and run additional modules from C2 infrastructure. Researchers also reconstructed its final payload behavior from memory artifacts, showing how the malware parses Chrome SQL and JSON stores and executes downloaded components via rundll32 to broaden theft and post-compromise capability.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
Mikhail Vasiliev was arrested in Canada in connection with the LockBit campaign. The report suggests he was likely an affiliate rather than a core LockBit leader.
Rhadamanthys was introduced on dark web forums and advertised by the actor using the alias "kingcrete2022" or "King Crete." The malware was marketed as an infostealer service to cybercriminal customers.
Multiple reports cited in the analysis state that Rhadamanthys has been active since late 2022, including distribution through fake software installers and malicious Google Ads.
LockBit claimed it compromised Accenture with insider assistance, stole 6TB of data, and later demanded $50 million. The group also claimed the stolen data could be used to access Accenture customers.
LockBit publicly launched LockBit 2.0, introducing a Tor-based admin panel and expanded affiliate tooling for scanning, log clearing, service termination, shadow-copy removal, and negotiation notifications.
LockBit developed "LockBit Red," publicly known as LockBit 2.0, and beta-tested it with select affiliates before public release.
An affiliate using the alias "Wexford" filed an arbitration complaint alleging a LockBit bug that appended ".lockbit" to network-host files without actually encrypting them.
LockBit and four other ransomware gangs announced a so-called "ransomware cartel," though the report assesses it as propaganda rather than a genuine shared operation.
LockBit sponsored a "Summer Paper Contest" on a Russian hacking forum, offering prizes from $1,000 to $5,000 as part of its marketing and reputation-building efforts.
The report describes an incident in which LockBit allegedly gained access through unpatched vulnerable VPN software and then brute-forced an administrative account.
After initially operating without affiliates, LockBit launched a ransomware-as-a-service program. This marked its transition into a broader affiliate-driven criminal ecosystem.
LockBit began operations in September 2019 under the name ABCD ransomware, appending the ".abcd" extension to encrypted files and using email-based ransom note contact methods.
During the writing of the Check Point report, version 0.5.1 was released, adding a clipper plugin and additional customization options for distributors.
Check Point analyzed Rhadamanthys version 0.5.0, documenting its expansion into broader spying functionality with a plugin system, keylogging, data spying, and enhanced wallet and browser theft.
Check Point published analysis describing Rhadamanthys' dark-web marketing, frequent updates, broad credential and wallet theft capabilities, and telemetry showing attempted infections against a Canadian government agency and an Indian energy-sector company.
Builds of Rhadamanthys surfaced that had reportedly been compiled about a month before the malware's official debut on cybercrime forums.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourceresearch.checkpoint.com
Open sourceanalyst1.com
Open sourceelis531989.medium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.