Check Point Research reported that the Rhadamanthys information stealer shares extensive technical overlap with the older Hidden Bee malware, indicating it is likely part of the same development lineage rather than a separate tool merely borrowing ideas. Researchers identified common design traits including custom executable formats, similar virtual filesystem structures, reused code and functions, identical component paths, steganographic payload delivery, LUA-based modules, named shared-memory mappings, and Heaven’s Gate techniques to load 64-bit code from 32-bit processes.
The analysis found that Rhadamanthys uses evolving custom module formats—RS and HS in older builds and XS1/XS2 in newer ones—to load staged components directly in memory, resolve imports, apply relocations, and handle exceptions outside normal PE execution. The malware decrypts embedded configuration data, performs anti-analysis checks, contacts command-and-control infrastructure for additional stages hidden in JPG or WAV files, and deploys modular stealing components including LUA scripts and .NET tools such as KeePassHax.dll and runtime.exe; Check Point also released converters to reconstruct PE files from the custom formats to support further analysis.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabz released a technical analysis of Rhadamanthys describing its three-stage loader flow, Q3VM-obfuscated variant, XTEA/RC4/LZSS/LZMA use, and embedded virtual filesystem modules used for relocation, unhooking, disk execution, and injection. The report also documented main-module components including KeePass credential theft and a PowerShell execution runtime.
On its publication date, Check Point Research released a technical analysis arguing that Rhadamanthys is likely a continuation of the Hidden Bee development lineage rather than merely inspired by it. The report documented overlaps in custom executable formats, virtual filesystem structures, reused code, steganographic payload delivery, LUA-based modules, and loading techniques.
Starting with version 4.5, Rhadamanthys substantially reworked its Quake 3 VM-based obfuscation by changing opcode mappings, altering syscall behavior, and using TEA-family decryption for stage 2. Recent versions also added a new anti-VM module, heur.bin, to detect virtualized or tampered analysis environments before later checks run.
The report says Rhadamanthys was first advertised on a black market in September 2022. The seller used the handle King Crete, also written as kingcrete2022, and communicated mostly in Russian.
Check Point's report says the last new Hidden Bee samples referenced in the analysis were observed in 2021. This marks the latest observation of new Hidden Bee activity mentioned in the source.
The report states that Hidden Bee first appeared around 2018. It was primarily distributed through the Underminer Exploit Kit and used custom executable formats named NE and NS.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 47 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceoutpost24.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.