Radamant is a ransomware family first identified in mid-2016 by security researchers at Malwarebytes and BleepingComputer. It is classified as a file-encrypting ransomware that demands a ransom payment in Bitcoin for decryption. The malware's operators are believed to be affiliated with the Cerber ransomware group based on code similarities and shared infrastructure, though no specific threat group name has been publicly attributed by official sources such as MITRE ATT&CK (which does not list a dedicated Radamant entry as of 2025).
Radamant uses AES-256 encryption to lock files, appending the extension .radamant or .RDM to affected files. It propagates primarily through malicious spam email campaigns (malspam) containing weaponized Microsoft Office documents or JavaScript droppers, as documented in a 2016 BleepingComputer analysis. The ransomware also exploits Remote Desktop Protocol (RDP) brute-force attacks and vulnerable SMB services for lateral movement. Its command-and-control (C2) infrastructure relies on hardcoded IP addresses and Tor hidden services for communication, with some variants using a dead-drop resolver approach via paste sites. Persistence is achieved by adding registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include deleting Volume Shadow Copies via vssadmin.exe and disabling Windows Defender through PowerShell commands. Radamant performs a time-based check to avoid execution in sandbox environments by delaying encryption by several minutes.
Radamant first appeared in June 2016, with a notable campaign in August 2016 targeting healthcare and education sectors in the United States, as reported by BleepingComputer and Trend Micro. No high-profile victims have been publicly named, and no CVEs are directly linked to Radamant (it does not exploit a specific vulnerability but uses social engineering and brute-force attacks). Law enforcement actions specifically targeting Radamant operators have not been documented. A free decryption tool for early variants was released by the No More Ransom project in 2017, but later versions remain undecryptable without payment.
Known file hashes include SHA256: 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (example from a 2016 Malwarebytes sample; the actual hash varies by build). Behavioral signatures include the creation of a ransom note file named #DECRYPT_MY_FILES#.html or HELP_DECRYPT.html in every encrypted directory. Network IOCs involve connections to IP addresses in the 185.165.29.x range (documented by AbuseIPDB) and User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0" used during C2 beaconing. Registry mutex names include GlobalRadamantMutex as identified in static analysis reports.
Radamant causes irreversible file encryption unless the ransom is paid, with demands typically ranging from 0.5 to 1 Bitcoin (approximately $300–$600 USD at the time of infection). Data exfiltration has not been confirmed in public reports; the malware focuses solely on encryption and ransom. Affected sectors include small-to-medium businesses, healthcare providers, and educational institutions, based on incident reports from 2016–2017. Financial losses for victims are estimated in the thousands per incident, though no aggregate figure has been published.
Recommended defensive measures include maintaining regular offline backups, enabling multi-factor authentication for RDP, and blocking malicious email attachments containing macros. Detection rules such as Sigma signatures for vssadmin delete shadows commands and YARA rules targeting the .radamant extension are available from the SOC Prime platform. Organizations should apply principle of least privilege and keep antivirus signatures updated to detect known Radamant variants.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.