HomeSecurityRHADAMANTHYS Stealer steals login credentials

RHADAMANTHYS Stealer steals login credentials

A new online campaign targeting Israeli users has brought to the fore the sophisticated information thief RHADAMANTHYS Stealer.

See also: TA547 hackers target Germany with Rhadamanthys malware

RHADAMANTHYS Stealer

RHADAMANTHYS Stealer, originating from Russian-speaking cybercriminals and offered as malware-as-a-service, excels at data extraction.

Recent samples and in-depth analysis reveal a complex infection chain and extensive payload capabilities, highlighting the evolving threat landscape and the need for robust defense against this malware.

The attack uses a social engineering tactic, using a Hebrew phishing email disguised as a legitimate notification from Calcalist and Mako .

The email exploits the urgency and fear of legal repercussions, falsely claiming copyright infringement, urging immediate action, which manipulates the psychology of users to bypass security measures by exploiting time pressure and anxiety about potential legal problems.

See also: New phishing campaign distributes Rhadamanthys malware

When executed, RHADAMANTHYS Stealer uses anti-parsing and anti-emulation tactics to prevent detection in sandbox, which initiates a multi-stage infection process, leveraging the provided msimg32.dll and a larger support file to establish itself on the compromised system.

RHADAMANTHYS Stealer steals login credentials

RHADAMANTHYS is a sophisticated information theft system that uses process injection into legitimate Windows to evade detection, using anti-analysis techniques such as virtual machine detection and error detection, as well as time evasion.

The malware persists through registry modification, steals sensitive data including credentials, browsing history, cryptocurrency information, and system details, and communicates with its C2 server using encrypted traffic over HTTPS and a non-standard port.

According to the researcher, it also acts as a downloader for subsequent malware payloads, posing a significant threat to compromised systems.

The malware exhibits malicious behavior on multiple system components by performing aggressive DNS lookups, possibly for evasive maneuvers or C2 communication.

See also: Rhadamanthys Stealer: Evolves with more powerful traits

An infostealer is a type of malware designed to collect sensitive information from a device without their consent. This software typically targets personal data such as usernames, passwords, credit card details, and other confidential information stored in browsers or applications. Once installed, infostealers can operate in the background, silently monitoring user activity and recording data. The stolen information is often sent to an external server where cybercriminals can access it for fraudulent purposes. Protecting yourself from infostealers requires strong cybersecurity measures, such as up-to-date antivirus software, regular system scans, and safe browsing practices to avoid falling victim to phishing attacks or malicious downloads.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS