HomeSecurityRhadamanthys Stealer: Evolving with more powerful features

Rhadamanthys Stealer: Evolves with more powerful traits

The developers of the Rhadamanthys Stealer information-stealing malware have recently released two major versions to add improvements and enhancements across the board, including new theft capabilities and improved detection evasion.

See also: MetaStealer malware targets Apple macOS in recent attacks

Rhadamanthys Stealer

Rhadamanthys is an information-stealing program first discovered in August 2022, targeting email, FTP, and banking account credentials.

The program is sold to cybercriminals via a subscription model, so it is distributed to targets through various channels, including malicious advertising, downloads from infected torrents, emails, YouTube , and other sources.

Although it initially didn't receive much attention in the saturated market of information-stealing applications, Rhadamanthys Stealer continued to improve, taking advantage of its modular nature to add new features as needed.

Check Point researchers have examined the two most recent versions of Rhadamanthys and reported the addition of several changes and features that expand its theft and espionage capabilities. Check Point analyzed version 0.5.0 of Rhadamanthys and reports that it introduced a new plugin system that allows for higher levels of customization for specific distribution needs.

Add-ons offer a variety of capabilities to malware, allowing cybercriminals to minimize their footprint by loading only what they need in each case.

The new add-on system shows a shift towards a more modular and customizable framework, as it allows attackers to install add-ons that are designed specifically for their targets, reacting to security measures identified during the identification stage or exploiting specific vulnerabilities.

See also: Lumma Stealer distributed via Discord CDN

An add-on that comes with Rhadamanthys is “Data Spy,” which can monitor successful RDP connection attempts and record the victim’s credentials.

Version 0.5.0 also brought fixes to the system targeting cryptocurrency wallets, and fixes to Discord token acquisition. Other notable improvements include improved data acquisition from browsers, updated search settings in the user panel, and the option to modify Telegram notifications .

Check Point says the malware loader has been rewritten to include anti-analysis checks, a built-in configuration, and a package of modules for the next stage (XS1).

characteristics

Further analysis revealed the existence of the following modules loaded by XS1, five of which are new in Rhadamanthys version 0.5.0 and focus on evasion.

Overall, version 0.5.1 introduces:

  • New Clipper plugin, which modifies cache data to direct cryptocurrency payments to the attacker
  • Telegram notification options for exporting the wallet key to the exported ZIP.
  • Ability to recover deleted Google.
  • Ability to avoid Windows Defender, including cloud protection, by cleaning its stub.

Rhadamanthys development is progressing rapidly, with each new version adding features that make the tool more threatening and more attractive to cybercriminals.

See also: CopperStealer Malware Crew Resurfaces with Two New Campaigns

Preventing and dealing with Rhadamanthys Stealer malware requires a series of security measures to be taken to protect computers and personal information. One of the most important preventive measures is updating software and operating systems on a regular basis. Updates often contain security fixes that can prevent Rhadamanthys Stealer malware from invading.

Additionally, installing a reliable antivirus software can help detect and remove Rhadamanthys Stealer malware from the computer. Antivirus programs are updated frequently to deal with new threats and protect the system from malware.

Additionally, users should be careful when browsing the internet. Avoiding visiting suspicious websites, opening spam emails, and clicking on unexpected attachments can reduce the risk of infection by Rhadamanthys Stealer malware.

Finally, regularly backing up important files and storing them in a safe location can be an effective protection against data loss due to Rhadamanthys Stealer malware.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS