HomeSecurityTA547 hackers target Germany with Rhadamanthys malware

TA547 hackers target Germany with Rhadamanthys malware

TA547 hackers appear to be targeting German companies with the info-stealer malware Rhadamanthys .

hackers TA547 Rhadamanthys malware

According to a report by Proofpoint , this is the first time this threat actor has been linked to such activity. Researchers observed the use of a PowerShell script that is likely generated by large language models (LLM) such as ChatGPT , Gemini , or CoPilot.

Impersonating the well-known German retailer Metro , hackers TA547 are sending phishing emails regarding supposed invoices. These emails, sent to multiple organizations in Germany, contained a password-protected ZIP file and an LNK file

See also: Byakugan info-stealer malware: How does it work?

When executed, the LNK file triggered PowerShell to launch a remote script. Ultimately, the Rhadamanthys malware was loaded and executed directly into the system.

According to the researchers, the PowerShell script exhibited some unusual characteristics, indicating possible LLM involvement.

This Rhadamanthys malware distribution campaign to companies in Germany shows a change in tactics by TA547 hackers, including the adoption of compressed LNKs and the introduction of this info-stealer. It also highlights how threat actors are leveraging content generated by LLM.

See also: Malicious ads distribute info-stealer malware on MacOS

TA547 hackers target Germany with Rhadamanthys malware

Protection from info-stealer malware

Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus

It is also important to keep your operating system and applications up to date. updates often include security fixes that can protect your computer from the latest threats (e.g. TA547 hackers).

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.

See also: Snake info-stealer malware: Distributed via Facebook messages

Also, don't forget to use firewalls and monitor network traffic , which will help you immediately identify suspicious activity.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it more difficult for TA547 hackers and other attackers to gain access to your account, even if they manage to steal your password.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS