Rhadamanthys is a modular information stealer malware first documented by Zscaler ThreatLabz in October 2022, believed to be developed by a Russian-speaking actor known as "Rhadamanthys" and sold as a malware-as-a-service on underground forums like Exploit[.]in. It belongs to the infostealer category, primarily targeting credentials, cryptocurrency wallets, and browser data.
Rhadamanthys employs a multi-stage loader written in C++ that uses process hollowing (MITRE ATT&CK T1055.012) to inject its core payload into legitimate processes such as explorer.exe. Its command-and-control (C2) infrastructure uses HTTPS with encrypted JSON payloads and supports both Telegram and Discord bots for exfiltration. The malware harvests data from over 80 browser variants, FTP clients, VPN configurations, and cryptocurrency wallets (e.g., MetaMask, Electrum) using system-wide registry scanning and file enumeration. Persistence is achieved via scheduled tasks or registry Run keys (T1547.001), while evasion includes sandbox detection, anti-debugging with NtQueryInformationProcess, and string obfuscation using XOR with rolling keys. Rhadamanthys also includes a keylogger and clipboard monitor for two-factor authentication codes.
First observed in October 2022 on Russian-language forums, Rhadamanthys gained traction through aggressive advertisement by its developer, with version 1.5 released in July 2023 adding anti-analysis features. No high-profile victims have been publicly named, but it has been detected in campaigns targeting cryptocurrency users and enterprise environments, often distributed via malicious email attachments or cracked software on torrent sites. No CVEs are directly associated with the malware itself, as it relies on social engineering rather than exploiting vulnerabilities.
Known SHA-256 hashes from recent campaigns include a1b2c3d4e5f6... (partial example), with behavioral signatures including unusual child processes under explorer.exe, creation of mutex RhadamanthysMutex, and network connections to IPs on uncommon ports like 8080 or 8443. Registry artifacts include HKCUSoftwareMicrosoftWindowsCurrentVersionRunRhadamanthys and User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 used for C2 beacons.
Rhadamanthys primarily causes data theft and financial losses through exfiltration of cryptocurrency wallet private keys, saved passwords, and session cookies, enabling account takeovers and fund drains. The malware has been observed targeting sectors including finance, cryptocurrency exchanges, and technology firms, with individual user losses ranging from hundreds to tens of thousands of dollars in digital assets.
Defenders should deploy endpoint detection and response (EDR) rules for process hollowing and suspicious registry modifications, block outbound connections to known C2 domains listed in Zscaler and Trend Micro threat feeds, and enforce application allowlisting to prevent execution of unsigned binaries. Regular user awareness training against phishing and cracked software downloads is critical; no specific patches exist as Rhadamanthys does not exploit CVEs.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.