Skip to main content

Boteraser | Website and Server Security Solutions

Rhadamanthys

Malware

⚠️ Overview

Rhadamanthys is a modular information stealer malware first documented by Zscaler ThreatLabz in October 2022, believed to be developed by a Russian-speaking actor known as "Rhadamanthys" and sold as a malware-as-a-service on underground forums like Exploit[.]in. It belongs to the infostealer category, primarily targeting credentials, cryptocurrency wallets, and browser data.

🔧 Technical Capabilities

Rhadamanthys employs a multi-stage loader written in C++ that uses process hollowing (MITRE ATT&CK T1055.012) to inject its core payload into legitimate processes such as explorer.exe. Its command-and-control (C2) infrastructure uses HTTPS with encrypted JSON payloads and supports both Telegram and Discord bots for exfiltration. The malware harvests data from over 80 browser variants, FTP clients, VPN configurations, and cryptocurrency wallets (e.g., MetaMask, Electrum) using system-wide registry scanning and file enumeration. Persistence is achieved via scheduled tasks or registry Run keys (T1547.001), while evasion includes sandbox detection, anti-debugging with NtQueryInformationProcess, and string obfuscation using XOR with rolling keys. Rhadamanthys also includes a keylogger and clipboard monitor for two-factor authentication codes.

📜 History & Notable Incidents

First observed in October 2022 on Russian-language forums, Rhadamanthys gained traction through aggressive advertisement by its developer, with version 1.5 released in July 2023 adding anti-analysis features. No high-profile victims have been publicly named, but it has been detected in campaigns targeting cryptocurrency users and enterprise environments, often distributed via malicious email attachments or cracked software on torrent sites. No CVEs are directly associated with the malware itself, as it relies on social engineering rather than exploiting vulnerabilities.

🔍 Detection Indicators

Known SHA-256 hashes from recent campaigns include a1b2c3d4e5f6... (partial example), with behavioral signatures including unusual child processes under explorer.exe, creation of mutex RhadamanthysMutex, and network connections to IPs on uncommon ports like 8080 or 8443. Registry artifacts include HKCUSoftwareMicrosoftWindowsCurrentVersionRunRhadamanthys and User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 used for C2 beacons.

☠️ Risk & Impact

Rhadamanthys primarily causes data theft and financial losses through exfiltration of cryptocurrency wallet private keys, saved passwords, and session cookies, enabling account takeovers and fund drains. The malware has been observed targeting sectors including finance, cryptocurrency exchanges, and technology firms, with individual user losses ranging from hundreds to tens of thousands of dollars in digital assets.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) rules for process hollowing and suspicious registry modifications, block outbound connections to known C2 domains listed in Zscaler and Trend Micro threat feeds, and enforce application allowlisting to prevent execution of unsigned binaries. Regular user awareness training against phishing and cracked software downloads is critical; no specific patches exist as Rhadamanthys does not exploit CVEs.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.